๐ฉ๐ช
stinpriza
2026-06-28 20:30:50
(3 days ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 10:08:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 06:08:04.276094 2026] [security2:error] [pid 13869:tid 13869] [client 2a03:4000:17:a15:d4db:fbff:fef4:8b7b:35530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.maprada92.com"] [uri "/.git/config"] [unique_id "ai_PBGAuf2b5yTxqS8jNGAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 03:48:14
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 23:48:06.177722 2026] [security2:error] [pid 13713:tid 13713] [client 2a03:4000:17:a15:d4db:fbff:fef4:8b7b:64694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.tomslawmd.com"] [uri "/.git/config"] [unique_id "aiuBdtUsRfY9bxwszpBn9gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 15:22:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 11:22:17.007200 2026] [security2:error] [pid 25983:tid 25983] [client 2a03:4000:17:a15:d4db:fbff:fef4:8b7b:64904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.a-absoluteseptic.com"] [uri "/.git/config"] [unique_id "aiQ7KeD0f-0ms0YBuILkKwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-05-26 13:47:42
(1 month ago)
Blocked by UFW (TCP on 8333)
Source port: 54684
Packet length: 80
This report (for 2a03:4000:0017:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 54684
Packet length: 80
This report (for 2a03:4000:0017:0a15:d4db:fbff:fef4:8b7b) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-07 10:23:32
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 06:23:23.600218 2026] [security2:error] [pid 15086:tid 15086] [client 2a03:4000:17:a15:d4db:fbff:fef4:8b7b:62014] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/backupwp.sql"] [unique_id "afxoG74_qzf1C0me1DlkmAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:03:36
(2 months ago)
2026-04-26 08:00:44,746 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:17:a15:d4db:fbff ...
show more
2026-04-26 08:00:44,746 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:17:a15:d4db:fbff:fef4:8b7b
2026-04-26 12:01:36,256 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:17:a15:d4db:fbff:fef4:8b7b
2026-04-26 18:01:33,923 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:17:a15:d4db:fbff:fef4:8b7b
2026-04-26 21:01:31,399 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:17:a15:d4db:fbff:fef4:8b7b
2026-04-27 00:03:35,446 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:17:a15:d4db:fbff:fef4:8b7b
show less
Brute-Force
๐บ๐ธ
xmission.com
2026-04-26 12:26:06
(2 months ago)
Blocked by UFW (TCP on 8333)
Source port: 32226
Packet length: 80
This report (for 2a03:4000:0017:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 32226
Packet length: 80
This report (for 2a03:4000:0017:0a15:d4db:fbff:fef4:8b7b) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ต๐ฑ
sefinek.net
2026-04-07 19:15:33
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from T1.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from T1.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: / | UA: Mozilla/5.0 (Android 10; Mobile; rv:140.0) Gecko/140.0 Firefox/140.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-02 19:39:45
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 15:39:40.097439 2026] [security2:error] [pid 10164:tid 10170] [client 2a03:4000:17:a15:d4db:fbff:fef4:8b7b:36582] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||datuinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "datuinc.com"] [uri "/datuinc_com.sql"] [unique_id "ac7F_NR0uXaoSUNeBb0ncQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-03-26 20:34:00
(3 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
xmission.com
2026-03-12 08:28:01
(3 months ago)
Blocked by UFW (TCP on 9999)
Source port: 61634
Packet length: 80
This report (for 2a03:4000:0017:0 ...
show more
Blocked by UFW (TCP on 9999)
Source port: 61634
Packet length: 80
This report (for 2a03:4000:0017:0a15:d4db:fbff:fef4:8b7b) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Ping of Death
๐บ๐ธ
TPI-Abuse
2026-03-03 18:03:16
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 13:03:07.832133 2026] [security2:error] [pid 1532:tid 1532] [client 2a03:4000:17:a15:d4db:fbff:fef4:8b7b:56880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jtagulator.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jtagulator.com"] [uri "/db_tagulator.sql"] [unique_id "aaciWysKjMWc8MVRyn75gQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 21:49:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:17:a15:d4db:fbff:fef4:8b7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 16:49:29.748767 2026] [security2:error] [pid 11323:tid 11323] [client 2a03:4000:17:a15:d4db:fbff:fef4:8b7b:56392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.passwordresearch.com"] [uri "/.git/config"] [unique_id "aYZh6fpWEjctbDnn8uK4VAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-05 22:59:25
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-02-04.
show less
Hacking
Web App Attack
SSH