This IP was reported 142 times. Confidence of
Abuse
is 11%: ?
11%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
142
times from
16 distinct
sources.
2a0b:f4c2:4::102 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 s ...
show more(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 05 09:50:49.987658 2026] [security2:error] [pid 1688:tid 1688] [client 2a0b:f4c2:4::102:42839] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thesteeldrumman.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thesteeldrumman.com"] [uri "/steeldrumman_com.sql"] [unique_id "aYSuSd6pwPFittWPHmN2KgAAAAw"]
show less
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 s ...
show more(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 06:30:01.980525 2026] [security2:error] [pid 30623:tid 30623] [client 2a0b:f4c2:4::102:41989] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nwuoregon.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nwuoregon.org"] [uri "/wuoregon_com.sql"] [unique_id "aYHcOdZ69eo03RjBEVa8yQAAAA4"]
show less
Blocked by UFW (TCP on 9999)
Source port: 1053
Packet length: 72
This report (for 2a0b:f4c2:0004:00 ...
show moreBlocked by UFW (TCP on 9999)
Source port: 1053
Packet length: 72
This report (for 2a0b:f4c2:0004:0000:0000:0000:0000:0102) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-02-01.
show less
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 s ...
show more(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 14 18:34:48.752531 2025] [security2:error] [pid 19330:tid 19330] [client 2a0b:f4c2:4::102:48943] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||riser-astrology.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "riser-astrology.com"] [uri "/er-astrology_com.sql"] [unique_id "aT9JmG5grp7e7SYz2vFyEwAAAAI"]
show less
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 s ...
show more(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 23:25:26.611531 2025] [security2:error] [pid 22925:tid 22936] [client 2a0b:f4c2:4::102:24401] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||howlerrock.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "howlerrock.com"] [uri "/k_com.sql"] [unique_id "aT48NoZFvfP6iD5W-Y8WAQAAAMA"]
show less
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 s ...
show more(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 13:42:02.665608 2025] [security2:error] [pid 7139:tid 7151] [client 2a0b:f4c2:4::102:5603] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||maryschalkdesign.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "maryschalkdesign.com"] [uri "/halkdesign_com.sql"] [unique_id "aT2zemH11TA74cwSQwYsBgAAAIg"]
show less
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 s ...
show more(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 04:02:55.208089 2025] [security2:error] [pid 4284:tid 4284] [client 2a0b:f4c2:4::102:53619] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||freeanddimesales.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "freeanddimesales.com"] [uri "/backupdb.sql"] [unique_id "aT0rv14z6Akf-fCg1zkdEwAAAAg"]
show less
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 s ...
show more(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 11:48:26.877236 2025] [security2:error] [pid 16070:tid 16070] [client 2a0b:f4c2:4::102:58769] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||puckerbottombikinis.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puckerbottombikinis.com"] [uri "/backupwp.sql"] [unique_id "aTxHWjQZl0SyQtMC6XMWwgAAAAc"]
show less
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 s ...
show more(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:4::102 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 10:53:52.136824 2025] [security2:error] [pid 18754:tid 18754] [client 2a0b:f4c2:4::102:50185] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.silalaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.silalaw.com"] [uri "/www_com.sql"] [unique_id "aTw6kAmn11ndBxK8gya4-gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 16 to
30
of 142 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ