๐บ๐ธ
ipblock.com
2026-03-26 22:31:00
(6 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-03-26 20:36:19
(6 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-10 04:52:55
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 00:52:48.427293 2026] [security2:error] [pid 14335:tid 14335] [client 2a0b:f4c2::14:65334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lkabookkeeping.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lkabookkeeping.com"] [uri "/db_eping.sql"] [unique_id "aa-joOLEUpzg7VBQfrYqOwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-27 11:56:03
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 06:55:56.438653 2026] [security2:error] [pid 28798:tid 28798] [client 2a0b:f4c2::14:48848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.hillerhome.com"] [uri "/.git/config"] [unique_id "aaGGTAIB6vtjkSEVjcCOnAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 09:13:28
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 04:13:24.464190 2026] [security2:error] [pid 20346:tid 20346] [client 2a0b:f4c2::14:20066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.sarahwhitecotton.com"] [uri "/.git/config"] [unique_id "aZ1rtLS_uoaROSMimtwhHwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 10:06:38
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 05:06:29.573222 2026] [security2:error] [pid 21239:tid 21249] [client 2a0b:f4c2::14:62356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.blastfuture.com"] [uri "/.git/config"] [unique_id "aZrVJUggDCDNVMMkAWqSVwAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-02-22 07:27:24
(7 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::14; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::14; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18; active_decisions=2; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scenario: http:scan); IP has active decisions total of 2, indicating repeated abuse patterns; Decision duration of 8280m suggests a long-term ban for sustained threat
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
ipblock.com
2026-02-21 07:12:00
(7 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 10:12:56
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 05:12:50.734126 2026] [security2:error] [pid 1929991:tid 1929991] [client 2a0b:f4c2::14:51874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tbvfc.com"] [uri "/.env.example"] [unique_id "aYcQIgWjD9QloQ40F-1DbAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 02:10:26
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 21:10:17.693675 2026] [security2:error] [pid 3492:tid 3492] [client 2a0b:f4c2::14:61240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.techsunlimited.net"] [uri "/.git/config"] [unique_id "aYafCQZErjKfQzHpzzjh1QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-02 10:16:46
(8 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
๐บ๐ธ
xmission.com
2026-02-02 09:47:36
(8 months ago)
Blocked by UFW (TCP on 8333)
Source port: 18058
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 18058
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0014) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-01-31 23:00:37
(8 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-30.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-30 07:18:27
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 02:18:23.032784 2026] [security2:error] [pid 7077:tid 7077] [client 2a0b:f4c2::14:64730] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thehealthyplaceclayton.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thehealthyplaceclayton.com"] [uri "/on_com.sql"] [unique_id "aXxbP9uts8r9-hdCF15FpQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-25 22:24:59
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::14 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 17:24:53.194639 2026] [security2:error] [pid 744820:tid 744820] [client 2a0b:f4c2::14:61036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.studiopilates.net"] [uri "/.git/config"] [unique_id "aXaYNb2mNTvit72nnksMTgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack