πΊπΈ
TPI-Abuse
2026-02-07 12:33:10
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 07:33:07.292221 2026] [security2:error] [pid 18666:tid 18666] [client 2a06:1700:0:12::4:34560] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||braunhausmedia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "braunhausmedia.com"] [uri "/dbmedia.sql"] [unique_id "aYcxAxBapYi_A_9uNIOJFQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-04 00:35:32
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210350) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 19:35:26.744301 2026] [security2:error] [pid 12939:tid 12939] [client 2a06:1700:0:12::4:28944] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||accredo.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "accredo.net"] [uri "/xmlrpc.php"] [unique_id "aYKUTo_WksshTQ9lBHyJYgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-01-31 23:00:52
(7 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-30.
show less
Hacking
Web App Attack
SSH
πΊπΈ
TPI-Abuse
2026-01-31 03:07:29
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 22:07:21.645973 2026] [security2:error] [pid 10981:tid 10981] [client 2a06:1700:0:12::4:43378] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||velocitymech.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "velocitymech.com"] [uri "/velocitym.sql"] [unique_id "aX1x6W3wT3WfnThebMPt7wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-01-29 18:12:53
(7 months ago)
Blocked by UFW (TCP on 8333)
Source port: 29856
Packet length: 80
This report (for 2a06:1700:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 29856
Packet length: 80
This report (for 2a06:1700:0000:0012:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-01-26 01:36:18
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 20:36:13.237564 2026] [security2:error] [pid 20865:tid 20865] [client 2a06:1700:0:12::4:19208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.ink2wear.com"] [uri "/.git/config"] [unique_id "aXbFDdZ9N-bxjpdE6fQYUQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-01-13 05:18:49
(7 months ago)
Blocked by UFW (TCP on 8333)
Source port: 50740
Packet length: 80
This report (for 2a06:1700:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 50740
Packet length: 80
This report (for 2a06:1700:0000:0012:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-01-05 23:34:47
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 05 18:34:38.250957 2026] [security2:error] [pid 831606:tid 831706] [client 2a06:1700:0:12::4:47542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||buick-reatta.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "buick-reatta.com"] [uri "/buic.sql"] [unique_id "aVxKjp-qPiNXa3zGvkOOpwAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-25 19:55:41
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 14:55:32.930560 2025] [security2:error] [pid 8245:tid 8245] [client 2a06:1700:0:12::4:6914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||protection4allsecurity.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "protection4allsecurity.com"] [uri "/back.sql"] [unique_id "aU2WtNMUT65qXE896zCdXAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-18 07:46:20
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 18 02:46:12.233635 2025] [security2:error] [pid 10507:tid 10507] [client 2a06:1700:0:12::4:65416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||losbarbarosdelnorte.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "losbarbarosdelnorte.com"] [uri "/.sql"] [unique_id "aUOxRD4bd8pu7oGPrdPzVwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-15 15:01:41
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 15 10:01:34.017563 2025] [security2:error] [pid 7057:tid 7057] [client 2a06:1700:0:12::4:36446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nearfieldchrist.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nearfieldchrist.com"] [uri "/backups.sql"] [unique_id "aUAizi0hn_aSD9nmNvZTfAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-14 03:25:59
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 22:25:56.208693 2025] [security2:error] [pid 21946:tid 21946] [client 2a06:1700:0:12::4:24908] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||goodfrequencies.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goodfrequencies.com"] [uri "/bck.sql"] [unique_id "aT4uRIudhyrso8kJKxtSbgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-13 07:32:28
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 02:32:18.345954 2025] [security2:error] [pid 14613:tid 14613] [client 2a06:1700:0:12::4:41832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jazziientertainment.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jazziientertainment.com"] [uri "/jazziientert.sql"] [unique_id "aT0Wgl6tjJSoFZawbQSdaQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-12 20:04:16
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 15:04:06.546864 2025] [security2:error] [pid 22694:tid 22694] [client 2a06:1700:0:12::4:51220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||robinsnestingplace.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "robinsnestingplace.net"] [uri "/robinsnestingpl.sql"] [unique_id "aTx1NudjkovlKRW7yXLK1QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-11 02:40:18
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 21:40:14.256377 2025] [security2:error] [pid 26128:tid 26128] [client 2a06:1700:0:12::4:55310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kairoslogammakmur.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kairoslogammakmur.com"] [uri "/slogammakmur.sql"] [unique_id "aTovDuvyMuZEInhO4ad5TQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack