๐บ๐ธ
TPI-Abuse
2026-08-17 09:18:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:18:05.111378 2026] [security2:error] [pid 11786:tid 11786] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:52082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lavozdominicana.com"] [uri "/.git/config"] [unique_id "aoLRzaX-sbafPglM_ciqnAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 11:40:32
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 07:40:25.354485 2026] [security2:error] [pid 1120:tid 1120] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:54288] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||armorcorp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "armorcorp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajE2KeN3dmLH6FF1XvzO5wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 11:22:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 07:22:47.243942 2026] [security2:error] [pid 26513:tid 26513] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:33424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.backspaced.com"] [uri "/.git/config"] [unique_id "ai_gh4685RqZ3OuCzhmDnAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 14:14:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:14:51.307885 2026] [security2:error] [pid 19263:tid 19263] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:48454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.wisk.org"] [uri "/.git/config"] [unique_id "aiLZ2wdV08G2FncHTbaa0AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 10:52:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 06:52:33.318237 2026] [security2:error] [pid 18323:tid 18323] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:36656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.lmga.net"] [uri "/.git/config"] [unique_id "aiKqcQPrc1eNtV_CdSDgbAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-05-24 01:44:00
(3 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 10:23:31
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 06:23:24.059069 2026] [security2:error] [pid 11196:tid 11196] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:33945] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/bck.sql"] [unique_id "afxoHAdbFgQJaFfWeCB0AgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-05-06 00:49:55
(3 months ago)
Blocked by UFW (TCP on 53110)
Source port: 9400
Packet length: 96
This report (for 2a03:4000:0046:0 ...
show more
Blocked by UFW (TCP on 53110)
Source port: 9400
Packet length: 96
This report (for 2a03:4000:0046:0197:b434:d3ff:fe68:d9e1) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-29 14:06:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 10:06:04.924056 2026] [security2:error] [pid 31612:tid 31612] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:30135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fernfield.com"] [uri "/wp-config.php.bak"] [unique_id "afIQTIvNnjgmOwMml3EQ7gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:03:39
(3 months ago)
2026-04-26 08:00:45,384 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:46:197:b434:d3ff ...
show more
2026-04-26 08:00:45,384 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:46:197:b434:d3ff:fe68:d9e1
2026-04-26 12:01:36,665 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:46:197:b434:d3ff:fe68:d9e1
2026-04-26 18:01:34,346 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:46:197:b434:d3ff:fe68:d9e1
2026-04-26 21:01:31,809 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:46:197:b434:d3ff:fe68:d9e1
2026-04-27 00:03:38,106 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:4000:46:197:b434:d3ff:fe68:d9e1
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-13 23:23:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 19:23:05.078727 2026] [security2:error] [pid 3790640:tid 3790640] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:18951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vmbinc.com"] [uri "/.git/config"] [unique_id "ad162RDN1vtM2d4rlqyX5AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-04-09 11:46:31
(4 months ago)
Blocked by UFW (TCP on 9999)
Source port: 14993
Packet length: 80
This report (for 2a03:4000:0046:0 ...
show more
Blocked by UFW (TCP on 9999)
Source port: 14993
Packet length: 80
This report (for 2a03:4000:0046:0197:b434:d3ff:fe68:d9e1) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Ping of Death
๐บ๐ธ
TPI-Abuse
2026-04-08 05:51:04
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 01:50:55.619888 2026] [security2:error] [pid 1950004:tid 1950004] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:41109] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||healingworksmassage.studio|F|2"] [data ".cfg"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "healingworksmassage.studio"] [uri "/wp-config.cfg"] [unique_id "adXsv1rOAqWKILkaYcDtswAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-03-26 20:24:48
(4 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-05 09:29:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:4000:46:197:b434:d3ff:fe68:d9e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 04:29:25.453941 2026] [security2:error] [pid 32377:tid 32377] [client 2a03:4000:46:197:b434:d3ff:fe68:d9e1:16368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fluff.hiidied.com"] [uri "/.git/config"] [unique_id "aalM9afWdMQlkVFSADtAowAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack