๐บ๐ธ
xmission.com
2026-08-29 02:06:12
(2 days ago)
Blocked by UFW (TCP on 35974)
Source port: 443
Packet length: 96
This report (for 2a02:c204:2195:20 ...
show more
Blocked by UFW (TCP on 35974)
Source port: 443
Packet length: 96
This report (for 2a02:c204:2195:2012:0000:0000:0000:0001) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-07-29 07:40:27
(1 month ago)
Blocked by UFW (TCP on 37594)
Source port: 443
Packet length: 96
This report (for 2a02:c204:2195:20 ...
show more
Blocked by UFW (TCP on 37594)
Source port: 443
Packet length: 96
This report (for 2a02:c204:2195:2012:0000:0000:0000:0001) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฎ๐น
VHosting
2026-06-25 15:14:23
(2 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
xmission.com
2026-05-31 11:53:32
(3 months ago)
Blocked by UFW (TCP on 8333)
Source port: 5315
Packet length: 80
This report (for 2a02:c204:2195:20 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 5315
Packet length: 80
This report (for 2a02:c204:2195:2012:0000:0000:0000:0001) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-05 11:00:17
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 05 07:00:11.832010 2026] [security2:error] [pid 15322:tid 15322] [client 2a02:c204:2195:2012::1:1955] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billymitchell.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billymitchell.com"] [uri "/mitchell_com.sql"] [unique_id "afnNuzz87TjifBowkPy-GwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:03:27
(4 months ago)
2026-04-26 08:00:43,928 fail2ban.actions [7718]: NOTICE [tor] Ban 2a02:c204:2195:2012::1
202 ...
show more
2026-04-26 08:00:43,928 fail2ban.actions [7718]: NOTICE [tor] Ban 2a02:c204:2195:2012::1
2026-04-26 12:01:35,727 fail2ban.actions [7718]: NOTICE [tor] Ban 2a02:c204:2195:2012::1
2026-04-26 18:01:33,411 fail2ban.actions [7718]: NOTICE [tor] Ban 2a02:c204:2195:2012::1
2026-04-26 21:01:30,873 fail2ban.actions [7718]: NOTICE [tor] Ban 2a02:c204:2195:2012::1
2026-04-27 00:03:25,831 fail2ban.actions [7718]: NOTICE [tor] Ban 2a02:c204:2195:2012::1
show less
Brute-Force
๐ฎ๐น
VHosting
2026-03-26 20:34:00
(5 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-23 13:35:27
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 08:35:22.416831 2026] [security2:error] [pid 12453:tid 12453] [client 2a02:c204:2195:2012::1:25619] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||artspacecleveland.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "artspacecleveland.com"] [uri "/ecleveland_db.sql"] [unique_id "aZxXmr43Xc3bmkjy7IfeOwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 17:20:56
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 12:20:48.633804 2026] [security2:error] [pid 7664:tid 7664] [client 2a02:c204:2195:2012::1:24247] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goldcountrygermanamericanclub.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goldcountrygermanamericanclub.org"] [uri "/b_prod.sql"] [unique_id "aYd0cIEjULWxtrZ6JBgsEwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-03 11:29:52
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 06:29:46.057995 2026] [security2:error] [pid 28128:tid 28128] [client 2a02:c204:2195:2012::1:36005] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nwuoregon.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nwuoregon.org"] [uri "/weekly.sql"] [unique_id "aYHcKnr5JboQcaB7w66Z6gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 19:30:42
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 14:30:36.698230 2026] [security2:error] [pid 3773456:tid 3773476] [client 2a02:c204:2195:2012::1:38929] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iacsb.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iacsb.com"] [uri "/backupwp.sql"] [unique_id "aWqR3AhE8Dw2auQP0aAC2QAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-14 11:22:52
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 06:22:45.559739 2026] [security2:error] [pid 12370:tid 12370] [client 2a02:c204:2195:2012::1:52819] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.naturalhomebuilders.com"] [uri "/.git/config"] [unique_id "aWd8hepaXddp6qGpb669xAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 22:18:25
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 17:18:21.249201 2025] [security2:error] [pid 7283:tid 7283] [client 2a02:c204:2195:2012::1:18267] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hawarcenter.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hawarcenter.com"] [uri "/hawarcent.sql"] [unique_id "aTtDLRvC_CcRrSEg9di8BgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 15:40:40
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 10:40:31.946607 2025] [security2:error] [pid 25667:tid 25667] [client 2a02:c204:2195:2012::1:36047] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||elgatocapa.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elgatocapa.com"] [uri "/backupdb.sql"] [unique_id "aThC77cCdTzzHDbcIBlRxQAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 20:09:36
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m- ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c204:2195:2012::1 (sortie-tor.a-n-o-n-y-m-e.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 15:09:30.764199 2025] [security2:error] [pid 31496:tid 31504] [client 2a02:c204:2195:2012::1:17933] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arizonasolutionsgroup.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arizonasolutionsgroup.com"] [uri "/backup_wp.sql"] [unique_id "aTSNet9RPvtReZsKa_c-hwAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack