๐บ๐ธ
xmission.com
2025-12-12 11:59:28
(8 months ago)
Blocked by UFW (TCP on 51472)
Source port: 49370
Packet length: 80
This report (for 2001:067c:0e28: ...
show more
Blocked by UFW (TCP on 51472)
Source port: 49370
Packet length: 80
This report (for 2001:067c:0e28:0001:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-12-12 05:33:11
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 00:33:00.478027 2025] [security2:error] [pid 23126:tid 23126] [client 2001:67c:e28:1::4:59790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fuentevictoria.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fuentevictoria.com"] [uri "/fu.sql"] [unique_id "aTupDGCmyaPTzk7cUJUKwwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 04:43:56
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 23:43:51.714863 2025] [security2:error] [pid 10335:tid 10335] [client 2001:67c:e28:1::4:57834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||braunhausmedia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "braunhausmedia.com"] [uri "/media_com.sql"] [unique_id "aTj6h2SlCWvfjxEs9IH4KAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 05:15:16
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 00:15:10.815059 2025] [security2:error] [pid 18803:tid 18803] [client 2001:67c:e28:1::4:51396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lilpiggiescardgame.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lilpiggiescardgame.com"] [uri "/e_com.sql"] [unique_id "aTewXqRo8WfDnuiwoMgXlgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 01:32:26
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 20:32:20.612527 2025] [security2:error] [pid 18545:tid 18561] [client 2001:67c:e28:1::4:39996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thecraftsycat.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecraftsycat.com"] [uri "/hecraftsycat_com.sql"] [unique_id "aTd8JOkWHLMNXOCY8I7ZaAAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-12-07 22:15:00
(8 months ago)
Blocked by UFW (TCP on 51472)
Source port: 47944
Packet length: 80
This report (for 2001:067c:0e28: ...
show more
Blocked by UFW (TCP on 51472)
Source port: 47944
Packet length: 80
This report (for 2001:067c:0e28:0001:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-12-07 19:42:18
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 14:42:12.495668 2025] [security2:error] [pid 20230:tid 20230] [client 2001:67c:e28:1::4:38532] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oldworldfineantiques.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oldworldfineantiques.com"] [uri "/weekly.sql"] [unique_id "aTXYlOc7WF059e5sYzuwqgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 10:51:37
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 05:51:34.167076 2025] [security2:error] [pid 4971:tid 4971] [client 2001:67c:e28:1::4:52120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||winformation.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "winformation.us"] [uri "/win.sql"] [unique_id "aTVcNmtRT8OUnwlADKVjKAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 01:07:21
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 20:07:14.444475 2025] [security2:error] [pid 11957:tid 11957] [client 2001:67c:e28:1::4:53634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||churchbehindthewalls.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "churchbehindthewalls.com"] [uri "/chu.sql"] [unique_id "aTTTQuboC4eBoUtUoPLiAQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 20:41:54
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 15:41:51.172648 2025] [security2:error] [pid 1939:tid 1939] [client 2001:67c:e28:1::4:54040] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grapplerunion.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grapplerunion.com"] [uri "/bck.sql"] [unique_id "aTSVD_E_HV8OGlCPaOHVHAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:01:14
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:01:08.683589 2025] [security2:error] [pid 27448:tid 27448] [client 2001:67c:e28:1::4:41142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ianmagarzo.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ianmagarzo.com"] [uri "/.sql"] [unique_id "aSaJlAGpSkyBOu7mqrtOFgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-11-18 11:29:13
(9 months ago)
Blocked by UFW (TCP on 51100)
Source port: 9001
Packet length: 2301
This report (for 2001:067c:0e28 ...
show more
Blocked by UFW (TCP on 51100)
Source port: 9001
Packet length: 2301
This report (for 2001:067c:0e28:0001:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2025-11-17 16:25:16
(9 months ago)
Blocked by UFW (TCP on 51472)
Source port: 36974
Packet length: 80
This report (for 2001:067c:0e28: ...
show more
Blocked by UFW (TCP on 51472)
Source port: 36974
Packet length: 80
This report (for 2001:067c:0e28:0001:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-11-15 11:09:46
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 06:09:40.423133 2025] [security2:error] [pid 21815:tid 21815] [client 2001:67c:e28:1::4:47396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.transcapitalsolutions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.transcapitalsolutions.com"] [uri "/lsolutions.sql"] [unique_id "aRhfdKNXm6_EGcwkBeqZwQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-11-13 04:30:18
(9 months ago)
Blocked by UFW (TCP on 45848)
Source port: 9001
Packet length: 2306
This report (for 2001:067c:0e28 ...
show more
Blocked by UFW (TCP on 45848)
Source port: 9001
Packet length: 2306
This report (for 2001:067c:0e28:0001:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan