๐ช๐ธ
gnom4ik
2026-04-05 18:34:14
(3 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::12; scenario=http:scan; verdict=valid_ban; confidence=0.92; ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::12; scenario=http:scan; verdict=valid_ban; confidence=0.92; categories=14,15,18,22; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high
show less
Port Scan
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-04-03 19:35:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 15:35:35.971571 2026] [security2:error] [pid 5114:tid 5114] [client 2a0b:f4c2::12:44292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.eiko-hamada.com"] [uri "/.git/config"] [unique_id "adAWh0g2TR3EU7vRRL1_SwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 20:50:42
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 16:50:33.397647 2026] [security2:error] [pid 3358:tid 3358] [client 2a0b:f4c2::12:30450] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edgecomix.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edgecomix.com"] [uri "/backup_wp.sql"] [unique_id "ac7Wmb15wQ-xKBBUKU0EAwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-03-26 20:36:19
(4 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-13 05:33:31
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 01:33:27.482414 2026] [security2:error] [pid 3549:tid 3549] [client 2a0b:f4c2::12:62096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.tlc-computing.com"] [uri "/.git/config"] [unique_id "abOhpxurLUT9EGcm0JfoSAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 01:40:19
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 21:40:15.546009 2026] [security2:error] [pid 28511:tid 28511] [client 2a0b:f4c2::12:49062] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mobileonlinecasinos.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mobileonlinecasinos.co"] [uri "/linecasinos_db.sql"] [unique_id "aa4k_4U_21ywcnH0meWPFAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-07 13:19:27
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 07 08:19:18.901972 2026] [security2:error] [pid 3674:tid 3674] [client 2a0b:f4c2::12:13196] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||diamondtrailerserv.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "diamondtrailerserv.com"] [uri "/dbrserv.sql"] [unique_id "aawl1t7jU3SLoO5Ey4pAzQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
OiledAmoeba
2026-03-06 14:25:59
(4 months ago)
2026/03/06 15:25:24 [error] 32#32: *338 open() "/var/www/wkd-ruhnke-cloud/.well-known/openpgpkey/ruh ...
show more
2026/03/06 15:25:24 [error] 32#32: *338 open() "/var/www/wkd-ruhnke-cloud/.well-known/openpgpkey/ruhnke.cloud/hu/54f6ry7x1qqtpor16txw5gdmdbbh6a73" failed (2: No such file or directory), client: 2a0b:f4c2::12, server: openpgpkey.ruhnke.cloud, request: "GET /.well-known/openpgpkey/ruhnke.cloud/hu/54f6ry7x1qqtpor16txw5gdmdbbh6a73?l=key-submission HTTP/1.0", host: "openpgpkey.ruhnke.cloud"
2026/03/06 15:25:51 [error] 32#32: *359 open() "/var/www/wkd-ruhnke-cloud/.well-known/openpgpkey/ruhnke.cloud/hu/54f6ry7x1qqtpor16txw5gdmdbbh6a73" failed (2: No such file or directory), client: 2a0b:f4c2::12, server: openpgpkey.ruhnke.cloud, request: "GET /.well-known/openpgpkey/ruhnke.cloud/hu/54f6ry7x1qqtpor16txw5gdmdbbh6a73?l=key-submission HTTP/1.0", host: "openpgpkey.ruhnke.cloud"
...
show less
Brute-Force
๐บ๐ธ
ipblock.com
2026-03-01 02:41:00
(4 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 16:41:48
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 11:41:42.847647 2026] [security2:error] [pid 4878:tid 4878] [client 2a0b:f4c2::12:60808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.dokuzadabirdeniz.com"] [uri "/.git/config"] [unique_id "aZsxxvqvUx2yC_FLnNNbbQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-21 14:41:37
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 09:41:32.463585 2026] [security2:error] [pid 10176:tid 10176] [client 2a0b:f4c2::12:45192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||waterspell.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "waterspell.net"] [uri "/pell_com.sql"] [unique_id "aZnEHIjQX7sTIDhxXXLGQQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 20:23:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 15:23:35.091380 2026] [security2:error] [pid 8458:tid 8486] [client 2a0b:f4c2::12:51366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.antidote-it.com"] [uri "/.git/config"] [unique_id "aYZNx02bibxAijoF3CC6cgAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-02-03 04:25:49
(5 months ago)
Blocked by UFW (TCP on 8333)
Source port: 19534
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 19534
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0012) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-01-30 23:02:14
(6 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-29.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-30 10:33:56
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 05:33:48.812166 2026] [security2:error] [pid 14488:tid 14488] [client 2a0b:f4c2::12:21502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||artspacecleveland.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "artspacecleveland.org"] [uri "/artspace.sql"] [unique_id "aXyJDCUgvb5An2rD7NiQXwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack