๐บ๐ธ
xmission.com
2026-07-14 04:59:53
(2 months ago)
Blocked by UFW (TCP on 59514)
Source port: 80
Packet length: 1500
This report (for 2620:0007:6001:0 ...
show more
Blocked by UFW (TCP on 59514)
Source port: 80
Packet length: 1500
This report (for 2620:0007:6001:0000:0000:ffff:c759:e652) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-07 11:01:23
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 06:01:16.446038 2026] [security2:error] [pid 10975:tid 10975] [client 2620:7:6001::ffff:c759:e652:34912] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boaredraven.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boaredraven.com"] [uri "/bo.sql"] [unique_id "aV48_PbIoytWjJnyIDZyfQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-20 20:31:27
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 20 15:31:20.205924 2025] [security2:error] [pid 640:tid 640] [client 2620:7:6001::ffff:c759:e652:57600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bamedica.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bamedica.com"] [uri "/bame.sql"] [unique_id "aUcHmFhgR7kLw2yC9jPbHgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-12 22:53:10
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 17:53:03.541734 2025] [security2:error] [pid 20110:tid 20110] [client 2620:7:6001::ffff:c759:e652:49586] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||outeraspect.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "outeraspect.com"] [uri "/outerasp.sql"] [unique_id "aTycz1Ifu45OSI6Rvi8HfQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 07:20:50
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 02:20:44.140324 2025] [security2:error] [pid 19369:tid 19369] [client 2620:7:6001::ffff:c759:e652:34656] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||campos.tv|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "campos.tv"] [uri "/c.sql"] [unique_id "aTpwzFCHprKbqvIYEF3KqQAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 00:54:24
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 07 20:54:06.605495 2025] [security2:error] [pid 4049202:tid 4049202] [client 2620:7:6001::ffff:c759:e652:38700] [client 2620:7:6001::ffff:c759:e652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fishleadership.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fishleadership.org"] [uri "/adminer.sql"] [unique_id "aBwArmvI9E33A4apTB12awAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-04 08:36:01
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 04:35:44.730328 2025] [security2:error] [pid 1832120:tid 1832193] [client 2620:7:6001::ffff:c759:e652:52084] [client 2620:7:6001::ffff:c759:e652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rwabutaza.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rwabutaza.com"] [uri "/migration.sql"] [unique_id "aBcm4FTNDHuG7EM2Q50krwAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-23 17:13:31
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 13:13:14.234091 2025] [security2:error] [pid 4183:tid 4183] [client 2620:7:6001::ffff:c759:e652:60888] [client 2620:7:6001::ffff:c759:e652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mcarrollcommunications.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mcarrollcommunications.com"] [uri "/administrator/backups/database.sql"] [unique_id "aAkfqnxvWLhCmcayjjF38wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-24 15:22:05
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 11:22:02.095264 2025] [security2:error] [pid 3178490:tid 3178490] [client 2620:7:6001::ffff:c759:e652:54990] [client 2620:7:6001::ffff:c759:e652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||golfmastercanada.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "golfmastercanada.com"] [uri "/database.sql"] [unique_id "Z-F4mvPzwCu0hriEwedB9AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-25 18:56:35
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e652 (tor29.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 25 14:56:30.277862 2024] [security2:error] [pid 10054:tid 10054] [client 2620:7:6001::ffff:c759:e652:57176] [client 2620:7:6001::ffff:c759:e652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||susanleeward.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "susanleeward.com"] [uri "/susanleew.sql"] [unique_id "Zst-XtBBv67P_OVGMsyQ3wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
beehivesafety
2024-02-09 18:02:50
(2 years ago)
Threat Blocked by BeeHive from (ASN:62744) (Network:QUINTEX) (Host:sentri.beehive.systems) (Method:G ...
show more
Threat Blocked by BeeHive from (ASN:62744) (Network:QUINTEX) (Host:sentri.beehive.systems) (Method:GET) (Protocol:HTTP/1.1) (Timestamp:2024-02-09T18:02:50Z)
show less
Open Proxy
VPN IP
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
mawan
2023-06-18 10:14:07
(3 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack