πΊπΈ
TPI-Abuse
2026-06-05 14:17:38
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:17:32.122212 2026] [security2:error] [pid 18591:tid 18591] [client 2a0b:f4c2::10:4240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.drowninglovers.com"] [uri "/.git/config"] [unique_id "aiLafL336Pwd5bLJZehPMAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-30 21:23:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 17:23:49.861567 2026] [security2:error] [pid 919:tid 919] [client 2a0b:f4c2::10:43694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.notariaramirez.cl"] [uri "/.git/config"] [unique_id "ahtVZXI47k6qmyk3XMGDXwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-05-22 14:53:43
(3 months ago)
Blocked by UFW (TCP on 8333)
Source port: 58834
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 58834
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0010) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
ipblock.com
2026-05-13 05:00:00
(4 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-06 19:15:41
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 15:15:34.644201 2026] [security2:error] [pid 26249:tid 26249] [client 2a0b:f4c2::10:60882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bluemarineboats.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bluemarineboats.com"] [uri "/backupwp.sql"] [unique_id "afuTVhynP0ZfJuvbPN5KjwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-29 14:06:24
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 10:06:19.210375 2026] [security2:error] [pid 29229:tid 29229] [client 2a0b:f4c2::10:42962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fernfield.com"] [uri "/wp-config.phpd"] [unique_id "afIQW0HcJsp1NJmO01VP_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-27 15:07:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 11:07:31.688142 2026] [security2:error] [pid 21195:tid 21195] [client 2a0b:f4c2::10:2714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.lucypower.com"] [uri "/.git/config"] [unique_id "ae97s6U5a2dIrJ52km3ocAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:04:33
(4 months ago)
2026-04-26 08:00:53,881 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::10
2026-04-26 1 ...
show more
2026-04-26 08:00:53,881 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::10
2026-04-26 12:01:41,815 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::10
2026-04-26 18:01:39,469 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::10
2026-04-26 21:01:38,718 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::10
2026-04-27 00:04:27,788 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::10
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-04-26 09:56:36
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 05:56:31.372109 2026] [security2:error] [pid 4040:tid 4040] [client 2a0b:f4c2::10:39448] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||avienhowell.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "avienhowell.com"] [uri "/avienhow.sql"] [unique_id "ae3hT-CBdLjGuigxg5q8ywAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
4server
2026-04-15 16:46:01
(5 months ago)
[WedApr1518:45:57.3022642026][security2:error][pid953282:tid953306][client2a0b:f4c2::10:0]ModSecurit ...
show more
[WedApr1518:45:57.3022642026][security2:error][pid953282:tid953306][client2a0b:f4c2::10:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\^/wp-content/plugins/[\^/] /\(readme\\\\\\\\.txt\|changelog\\\\\\\\.txt\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"359\"][id\"960828\"][msg\"WordPresspluginenumerationblocked\"][hostname\"www.benvenutialfood.ch\"][uri\"/wp-content/plugins/revslider/readme.txt\"][unique_id\"ad_AxVipDbF2jqYhuEFUcAAAAFY\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-11 21:38:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 17:38:30.575346 2026] [security2:error] [pid 4095294:tid 4095294] [client 2a0b:f4c2::10:16194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "telecompros.net"] [uri "/wp-config.phpOLD"] [unique_id "adq_ViZyGAirBlgGUxw1_gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-09 16:38:12
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::10 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 12:38:04.814338 2026] [security2:error] [pid 4193531:tid 4193531] [client 2a0b:f4c2::10:24364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staben.com"] [uri "/wp-config.php.info"] [unique_id "adfV7KJe8myZY_pZc1pH9gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-04-09 01:45:52
(5 months ago)
Blocked by UFW (TCP on 8333)
Source port: 49758
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 49758
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0010) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πͺπΈ
gnom4ik
2026-04-05 13:05:14
(5 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::10; scenario=http:scan; verdict=valid_ban; confidence=0.92; ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::10; scenario=http:scan; verdict=valid_ban; confidence=0.92; categories=14,15,18,22; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high
show less
Port Scan
Hacking
Brute-Force
SSH
πΊπΈ
ipblock.com
2026-03-26 21:31:00
(5 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack