๐บ๐ธ
xmission.com
2026-07-14 05:09:37
(2 months ago)
Blocked by UFW (TCP on 54720)
Source port: 83
Packet length: 1500
This report (for 2620:0007:6001:0 ...
show more
Blocked by UFW (TCP on 54720)
Source port: 83
Packet length: 1500
This report (for 2620:0007:6001:0000:0000:ffff:c759:e658) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-12 12:14:19
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 07:14:14.485021 2026] [security2:error] [pid 17133:tid 17225] [client 2620:7:6001::ffff:c759:e658:58032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.gell.us"] [uri "/.git/config"] [unique_id "aWTlliPldMa9SqAMimpsgQAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-09 13:40:12
(8 months ago)
Detected Hacking, SQL Injection or general Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 20:45:25
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 15:45:19.427771 2025] [security2:error] [pid 21682:tid 21682] [client 2620:7:6001::ffff:c759:e658:57040] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bigislandhawaiirealestate.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bigislandhawaiirealestate.com"] [uri "/bigislandhawaiirealest.sql"] [unique_id "aVLoX8akL5WvYhc9kL-IbQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 14:30:54
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 09:30:48.235940 2025] [security2:error] [pid 29429:tid 29429] [client 2620:7:6001::ffff:c759:e658:55572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crittergetterpestcontrol.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crittergetterpestcontrol.com"] [uri "/erpestcontrol_com.sql"] [unique_id "aVKQmESOX09jj7TcE-zCngAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-13 19:18:27
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 14:18:20.976112 2025] [security2:error] [pid 27385:tid 27385] [client 2620:7:6001::ffff:c759:e658:42212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||utd.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "utd.net"] [uri "/ut.sql"] [unique_id "aT27_GGOYmzGtOpkKo_hGAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-22 12:15:22
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 22 08:15:15.539801 2025] [security2:error] [pid 3585163:tid 3585163] [client 2620:7:6001::ffff:c759:e658:54772] [client 2620:7:6001::ffff:c759:e658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||barcelonarider.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barcelonarider.com"] [uri "/adminer.sql"] [unique_id "aC8VU46HXQHOeOWMhez40gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-08 10:50:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 08 06:50:39.147718 2025] [security2:error] [pid 24234:tid 24336] [client 2620:7:6001::ffff:c759:e658:58414] [client 2620:7:6001::ffff:c759:e658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jeanpaullederer.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeanpaullederer.com"] [uri "/db.sql"] [unique_id "Z_T_fxVFXTFnD3aMnYFkQwAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-05 22:56:13
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 05 18:56:08.347833 2025] [security2:error] [pid 20205:tid 20205] [client 2620:7:6001::ffff:c759:e658:47506] [client 2620:7:6001::ffff:c759:e658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cubbylure.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cubbylure.com"] [uri "/db.sql"] [unique_id "Z_G1CKPsPb_7OGsVHm5QoAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-21 07:16:39
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 21 03:16:31.475671 2025] [security2:error] [pid 29304:tid 29304] [client 2620:7:6001::ffff:c759:e658:53268] [client 2620:7:6001::ffff:c759:e658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dw-consultancy.nl|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dw-consultancy.nl"] [uri "/wp-content/db.sql"] [unique_id "Z90STwBRyZVzGsAHrxtM4gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-21 03:09:24
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 20 23:09:17.174965 2025] [security2:error] [pid 27881:tid 27881] [client 2620:7:6001::ffff:c759:e658:51746] [client 2620:7:6001::ffff:c759:e658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||meliaethelwoodard.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "meliaethelwoodard.com"] [uri "/df_main.sql"] [unique_id "Z9zYXZntQGZy6lznYx1LlAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-29 02:51:18
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 28 22:51:12.419211 2024] [security2:error] [pid 27578:tid 27585] [client 2620:7:6001::ffff:c759:e658:60838] [client 2620:7:6001::ffff:c759:e658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thecraftsycat.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecraftsycat.com"] [uri "/raftsycat.sql"] [unique_id "Zs_iIEhakSS5vhunFSePpgAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MHuiG
2024-08-25 00:39:50
(2 years ago)
The IP has triggered Cloudflare WAF. action: managed_challenge source: country clientAsn: 62744 clie ...
show more
The IP has triggered Cloudflare WAF. action: managed_challenge source: country clientAsn: 62744 clientASNDescription: QUINTEX clientCountryName: T1 clientIP: 2620:7:6001::ffff:c759:e658 clientRequestHTTPHost: nextchat.mhuig.top clientRequestHTTPMethodName: GET clientRequestHTTPProtocol: HTTP/1.1 clientRequestPath: /favicon.ico clientRequestQuery: datetime: 2024-08-24T23:01:05Z rayName: 8b86f653da9c465f ruleId: country userAgent: Mozilla/5.0 (iPhone; CPU iPhone OS 17_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Mobile/15E148 Safari/604.1. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Open Proxy
VPN IP
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 06:07:27
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 02:07:22.745466 2024] [security2:error] [pid 26723:tid 26723] [client 2620:7:6001::ffff:c759:e658:58434] [client 2620:7:6001::ffff:c759:e658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.vicmackenzie.com"] [uri "/.git/config"] [unique_id "ZsGPmm1qG3uesKMwHZVM2wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-07 19:20:54
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com) ...
show more
(mod_security) mod_security (id:234930) triggered by 2620:7:6001::ffff:c759:e658 (tor39.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 07 15:20:47.344508 2024] [security2:error] [pid 12507:tid 12575] [client 2620:7:6001::ffff:c759:e658:50188] [client 2620:7:6001::ffff:c759:e658] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||tomithai.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "tomithai.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ZrPJDyvUttgGlrrw4Vv1IgAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack