๐บ๐ธ
xmission.com
2026-07-25 18:52:44
(1 month ago)
Blocked by UFW (TCP on 8333)
Source port: 50666
Packet length: 80
This report (for 2600:3c04:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 50666
Packet length: 80
This report (for 2600:3c04:0000:0000:f03c:95ff:fe41:d42c) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-07-04 13:37:05
(2 months ago)
Blocked by UFW (TCP on 58928)
Source port: 443
Packet length: 1250
This report (for 2600:3c04:0000: ...
show more
Blocked by UFW (TCP on 58928)
Source port: 443
Packet length: 1250
This report (for 2600:3c04:0000:0000:f03c:95ff:fe41:d42c) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-11 20:48:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.loc ...
show more
(mod_security) mod_security (id:210492) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 16:48:43.476421 2026] [security2:error] [pid 2358:tid 2358] [client 2600:3c04::f03c:95ff:fe41:d42c:42336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.summithost.com"] [uri "/.git/config"] [unique_id "aisfKwqbXgYeudacU5FqNQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:02:03
(4 months ago)
2026-04-26 08:00:27,533 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c04::f03c:95ff:fe41: ...
show more
2026-04-26 08:00:27,533 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c04::f03c:95ff:fe41:d42c
2026-04-26 12:01:25,670 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c04::f03c:95ff:fe41:d42c
2026-04-26 18:01:23,464 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c04::f03c:95ff:fe41:d42c
2026-04-26 21:01:20,500 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c04::f03c:95ff:fe41:d42c
2026-04-27 00:02:02,119 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c04::f03c:95ff:fe41:d42c
show less
Brute-Force
๐ฎ๐น
VHosting
2026-03-26 21:23:39
(5 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-02-23 23:34:00
(6 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
ph
2026-02-12 03:06:11
(7 months ago)
Bad web bot attempting to run wp-admin on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 17:19:29
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 12:19:24.629512 2026] [security2:error] [pid 28829:tid 28829] [client 2600:3c04::f03c:95ff:fe41:d42c:35940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goldcountrygermanamericanclub.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goldcountrygermanamericanclub.org"] [uri "/americanclub_db.sql"] [unique_id "aYd0HEs7xlGzF6sxp9Wo6gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ป๐ช
Viejest
2026-02-02 11:59:00
(7 months ago)
Coordinated Attacks with TOR net
Web App Attack
๐จ๐ฆ
1gz
2025-12-17 03:05:44
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /auth/verify/L9mP4KIdJ4SQe2kq8RcSMvS2XjIyd69X
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-16 15:59:34
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 16 10:59:31.836129 2025] [security2:error] [pid 21839:tid 21839] [client 2600:3c04::f03c:95ff:fe41:d42c:56528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidharrisgriffith.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidharrisgriffith.com"] [uri "/sgriffith_com.sql"] [unique_id "aUGB4xhovXaoOKWxRNxxpwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-15 09:41:59
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 15 04:41:53.935447 2025] [security2:error] [pid 16550:tid 16550] [client 2600:3c04::f03c:95ff:fe41:d42c:36452] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raintechgutters.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raintechgutters.com"] [uri "/gutters.sql"] [unique_id "aT_X4RZt5Hx4S6CR7d8BMQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 00:11:18
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.lin ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.linuxenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 19:11:12.176508 2025] [security2:error] [pid 3927:tid 3946] [client 2600:3c04::f03c:95ff:fe41:d42c:39010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||whitecrosslibrary.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "whitecrosslibrary.com"] [uri "/library_com.sql"] [unique_id "aTN0oAuo3vAuNYGZZH8J3gAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2025-11-29 17:29:47
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 63949 (AKAMAI-LINODE-AP ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 63949 (AKAMAI-LINODE-AP Akamai Connected Cloud)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2025-11-29T17:25:20Z
Ray ID: 9a63cdc359ffac69
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-21 18:03:03
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.lin ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c04::f03c:95ff:fe41:d42c (tor-exit.ca.linuxenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 13:02:59.199935 2025] [security2:error] [pid 23949:tid 23949] [client 2600:3c04::f03c:95ff:fe41:d42c:50680] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mariettacaseyclub.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mariettacaseyclub.org"] [uri "/ttacaseyclub.sql"] [unique_id "aSCpU5Meh3DxLr6STXbmDAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack