๐บ๐ธ
TPI-Abuse
2026-04-30 09:32:04
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 05:31:58.501912 2026] [security2:error] [pid 23540:tid 23569] [client 2a00:1b88:4::2:51052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "la.productions"] [uri "/wp-config.php.backup"] [unique_id "afMhjsY37fAHwfbSYS0oFQAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 15:42:30
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 11:42:19.447353 2026] [security2:error] [pid 4925:tid 4925] [client 2a00:1b88:4::2:49114] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/americanex.sql"] [unique_id "ae-D24A5QObVbKlR2LkB4QAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:03:14
(4 months ago)
2026-04-26 08:00:42,077 fail2ban.actions [7718]: NOTICE [tor] Ban 2a00:1b88:4::2
2026-04-26 ...
show more
2026-04-26 08:00:42,077 fail2ban.actions [7718]: NOTICE [tor] Ban 2a00:1b88:4::2
2026-04-26 12:01:34,622 fail2ban.actions [7718]: NOTICE [tor] Ban 2a00:1b88:4::2
2026-04-26 18:01:32,336 fail2ban.actions [7718]: NOTICE [tor] Ban 2a00:1b88:4::2
2026-04-26 21:01:29,776 fail2ban.actions [7718]: NOTICE [tor] Ban 2a00:1b88:4::2
2026-04-27 00:03:12,484 fail2ban.actions [7718]: NOTICE [tor] Ban 2a00:1b88:4::2
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-26 12:48:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 08:47:57.436234 2026] [security2:error] [pid 7038:tid 7038] [client 2a00:1b88:4::2:42496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kavahawaii.com"] [uri "/wp-config.php~~~"] [unique_id "ae4Jfe5DCy1Rsnt1rVO-nAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 02:40:45
(4 months ago)
(mod_security) mod_security (id:210831) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210831) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 22:40:38.211731 2026] [security2:error] [pid 29056:tid 29056] [client 2a00:1b88:4::2:39004] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.linearconceptsllc.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.linearconceptsllc.com"] [uri "/robots.txt"] [unique_id "ae17Ju8zRmgwFVKaiD6OTwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-04-24 15:44:46
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from T1.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from T1.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.backup.txt
UA: Mozilla/5.0 (Linux; Android 4.1.2; SGH-I727R Build/JZO54K) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.169 Mobile Safari/537.22
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-04-24 10:48:00
(4 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 00:55:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 20:55:31.084566 2026] [security2:error] [pid 3280387:tid 3280387] [client 2a00:1b88:4::2:47238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbcash.com"] [uri "/wp-config.php.fr"] [unique_id "aeluA3zIPQHeEJNzEdkNfQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-18 08:54:04
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 04:53:54.638229 2026] [security2:error] [pid 3432944:tid 3432964] [client 2a00:1b88:4::2:48656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "annacaird.com"] [uri "/wp-config.phpb"] [unique_id "aeNGotLcc9wEXnhDhJzTTQAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-04-14 19:42:39
(5 months ago)
[TueApr1421:42:34.1778632026][security2:error][pid179038:tid179045][client2a00:1b88:4::2:0]ModSecuri ...
show more
[TueApr1421:42:34.1778632026][security2:error][pid179038:tid179045][client2a00:1b88:4::2:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\^/wp-content/plugins/[\^/] /\(readme\\\\\\\\.txt\|changelog\\\\\\\\.txt\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"359\"][id\"960828\"][msg\"WordPresspluginenumerationblocked\"][hostname\"edelhaut.ch\"][uri\"/wp-content/plugins/marra-core/readme.txt\"][unique_id\"ad6YquRmDEhpYb5Ch7HevwAAAUQ\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 05:50:41
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 01:50:33.813439 2026] [security2:error] [pid 1942162:tid 1942162] [client 2a00:1b88:4::2:41374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healingworksmassage.studio"] [uri "/wp-config.bak"] [unique_id "adXsqcRQelQiTPKbT4sBxAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 04:09:30
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 00:09:24.603783 2026] [security2:error] [pid 13217:tid 13217] [client 2a00:1b88:4::2:50876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virtualvideo.org"] [uri "/.git/config"] [unique_id "acil9H4sFeCO0oUk4fp9ngAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-03-28 16:33:07
(5 months ago)
Blocked by UFW (TCP on 8333)
Source port: 57004
Packet length: 80
This report (for 2a00:1b88:0004:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 57004
Packet length: 80
This report (for 2a00:1b88:0004:0000:0000:0000:0000:0002) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฎ๐น
VHosting
2026-03-27 01:06:53
(5 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-26 21:54:31
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2a00:1b88:4::2 (marcuse.nos-oignons.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 17:54:25.253851 2026] [security2:error] [pid 29581:tid 29581] [client 2a00:1b88:4::2:37534] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desertautoworks.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desertautoworks.com"] [uri "/desertauto.sql"] [unique_id "acWrEXuhM5DkFz1Y37zcbQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack