๐ฉ๐ช
HandyTreff.de
2026-07-24 12:42:48
(1 month ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -73.334 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -73.334 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
xmission.com
2026-07-21 06:19:20
(1 month ago)
Blocked by UFW (TCP on 37934)
Source port: 83
Packet length: 2294
This report (for 2620:0007:6001:0 ...
show more
Blocked by UFW (TCP on 37934)
Source port: 83
Packet length: 2294
This report (for 2620:0007:6001:0000:0000:ffff:c759:e64c) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-26 01:27:37
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 20:27:30.964421 2026] [security2:error] [pid 2721925:tid 2722011] [client 2620:7:6001::ffff:c759:e64c:36906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.wwwhst.com"] [uri "/.git/config"] [unique_id "aXbDAqhZEsS7nllzwDJ2lQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-05 10:53:10
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 05 05:52:57.093826 2026] [security2:error] [pid 599:tid 668] [client 2620:7:6001::ffff:c759:e64c:55806] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||planmytrust.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "planmytrust.com"] [uri "/backupdb.sql"] [unique_id "aVuYCdaau5vXwKMHrvVyuwAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-03 18:59:35
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 13:59:29.870527 2026] [security2:error] [pid 15720:tid 15720] [client 2620:7:6001::ffff:c759:e64c:40982] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||angelaknightmusicproductions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "angelaknightmusicproductions.com"] [uri "/ons_com.sql"] [unique_id "aVlnEf7-xb0D7GqHOjooQQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-16 08:57:47
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 16 03:57:40.333755 2025] [security2:error] [pid 20405:tid 20405] [client 2620:7:6001::ffff:c759:e64c:56394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thorndikestudio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thorndikestudio.com"] [uri "/io.sql"] [unique_id "aUEfBGhwjJLJVDmddVi0lgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-15 10:30:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 06:30:40.926681 2025] [security2:error] [pid 1896554:tid 1896599] [client 2620:7:6001::ffff:c759:e64c:60048] [client 2620:7:6001::ffff:c759:e64c] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oilchangelafayette.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oilchangelafayette.com"] [uri "/3.sql"] [unique_id "aCXCUHBd9LjplYf42HC0MAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-04 16:55:39
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 04 12:55:32.321235 2025] [security2:error] [pid 12405:tid 12405] [client 2620:7:6001::ffff:c759:e64c:34334] [client 2620:7:6001::ffff:c759:e64c] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||premierveterinarysurgery.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "premierveterinarysurgery.com"] [uri "/db.sql"] [unique_id "Z_APBKH3MxlHNCGbM4pR0wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 03:04:02
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 23:03:57.769262 2024] [security2:error] [pid 11545:tid 11545] [client 2620:7:6001::ffff:c759:e64c:39872] [client 2620:7:6001::ffff:c759:e64c] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.elainebroussard.com"] [uri "/.git/config"] [unique_id "ZsFknfhLp8zLcO5qzpeKNAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-18 20:58:40
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e64c (tor23.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 18 16:58:31.251246 2024] [security2:error] [pid 14397] [client 2620:7:6001::ffff:c759:e64c:40538] [client 2620:7:6001::ffff:c759:e64c] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||puckerbikini.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puckerbikini.com"] [uri "/bikini.sql"] [unique_id "ZkkWd7umlwmx28nnN4C2wgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2023-08-02 21:34:54
(3 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack