๐บ๐ธ
xmission.com
2026-06-26 18:17:26
(3 months ago)
Blocked by UFW (TCP on 6881)
Source port: 44700
Packet length: 80
This report (for 2600:3c0b:0000:0 ...
show more
Blocked by UFW (TCP on 6881)
Source port: 44700
Packet length: 80
This report (for 2600:3c0b:0000:0000:f03c:95ff:fefa:bdff) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-06-25 10:05:00
(3 months ago)
Blocked by UFW (TCP on 6881)
Source port: 41172
Packet length: 80
This report (for 2600:3c0b:0000:0 ...
show more
Blocked by UFW (TCP on 6881)
Source port: 41172
Packet length: 80
This report (for 2600:3c0b:0000:0000:f03c:95ff:fefa:bdff) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-15 13:43:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.loc ...
show more
(mod_security) mod_security (id:210492) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 09:43:27.440670 2026] [security2:error] [pid 23371:tid 23371] [client 2600:3c0b::f03c:95ff:fefa:bdff:40530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.railsolutionsmexico.com"] [uri "/.git/config"] [unique_id "ajABf9MEDUuC-kinV3pm2wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:02:03
(5 months ago)
2026-04-26 08:00:27,731 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c0b::f03c:95ff:fefa: ...
show more
2026-04-26 08:00:27,731 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c0b::f03c:95ff:fefa:bdff
2026-04-26 12:01:25,782 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c0b::f03c:95ff:fefa:bdff
2026-04-26 18:01:23,583 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c0b::f03c:95ff:fefa:bdff
2026-04-26 21:01:20,634 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c0b::f03c:95ff:fefa:bdff
2026-04-27 00:02:02,942 fail2ban.actions [7718]: NOTICE [tor] Ban 2600:3c0b::f03c:95ff:fefa:bdff
show less
Brute-Force
๐ฎ๐น
VHosting
2026-03-26 20:36:19
(6 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-26 14:00:43
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 10:00:36.798323 2026] [security2:error] [pid 31805:tid 31876] [client 2600:3c0b::f03c:95ff:fefa:bdff:45250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cliffwheeler.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cliffwheeler.com"] [uri "/cliffwheeler_com.sql"] [unique_id "acU8BN8C8MbYyo0kMc8UzQAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-04 22:59:48
(7 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-02-03.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-12-30 18:09:42
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 13:09:35.372669 2025] [security2:error] [pid 1807:tid 1807] [client 2600:3c0b::f03c:95ff:fefa:bdff:55188] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||airdriedrivingschool.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "airdriedrivingschool.com"] [uri "/weekly.sql"] [unique_id "aVQVX5PLTedTlEPoodyuxQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-16 15:58:55
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 16 10:58:47.914111 2025] [security2:error] [pid 21839:tid 21839] [client 2600:3c0b::f03c:95ff:fefa:bdff:58628] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidharrisgriffith.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidharrisgriffith.com"] [uri "/rrisgriffith_com.sql"] [unique_id "aUGBtxhovXaoOKWxRNxxpQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-16 10:38:01
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 16 05:37:54.700085 2025] [security2:error] [pid 22604:tid 22604] [client 2600:3c0b::f03c:95ff:fefa:bdff:42926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||elpaco.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elpaco.net"] [uri "/backup_wp.sql"] [unique_id "aUE2gsS4tr-DEzS34d3DJgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-14 20:51:26
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 14 15:51:21.809883 2025] [security2:error] [pid 18423:tid 18423] [client 2600:3c0b::f03c:95ff:fefa:bdff:36104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deborahbein.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deborahbein.com"] [uri "/backup_wp.sql"] [unique_id "aT8jSdn1fpw6EFqfGgqQQwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 20:48:09
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 15:47:55.900053 2025] [security2:error] [pid 9003:tid 9147] [client 2600:3c0b::f03c:95ff:fefa:bdff:44784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||robotics4fun.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "robotics4fun.com"] [uri "/cs4fun_com.sql"] [unique_id "aTncewigHaGPbHRAbwJYigAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 07:19:52
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.loc ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.localenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 02:19:46.737036 2025] [security2:error] [pid 6073:tid 6092] [client 2600:3c0b::f03c:95ff:fefa:bdff:54476] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||maroontribe.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "maroontribe.com"] [uri "/ribe_com.sql"] [unique_id "aTkfEuZmqyM-vQLcyaf8JwAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 04:53:48
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.lin ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.linuxenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 23:53:42.219735 2025] [security2:error] [pid 16458:tid 16458] [client 2600:3c0b::f03c:95ff:fefa:bdff:50172] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bernsteinip.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bernsteinip.com"] [uri "/back.sql"] [unique_id "aTerVjTT-4TqGmjRw7abKgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 03:11:41
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.lin ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c0b::f03c:95ff:fefa:bdff (tor-exit.it.linuxenby.is): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 22:11:33.906045 2025] [security2:error] [pid 21626:tid 21654] [client 2600:3c0b::f03c:95ff:fefa:bdff:40654] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||woofnrose.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "woofnrose.com"] [uri "/e_com.sql"] [unique_id "aTTwZWJA2GR5bbAnlYWHmQAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack