๐น๐ท
neron
2026-07-25 06:27:07
(6 days ago)
CrowdSec blocked: http:scan detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 00:05:18
(2 weeks ago)
(mod_security) mod_security (id:211220) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:211220) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 20:05:06.137317 2026] [security2:error] [pid 13384:tid 13384] [client 2a0b:f4c2::15:15436] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<\\\\?(?!xml\\\\s)" at ARGS:vars[0]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "70"] [id "211220"] [rev "4"] [msg "COMODO WAF: PHP Injection Attack||icafe.bz.shafie.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icafe.bz.shafie.net"] [uri "/index.php"] [unique_id "alV9MpLX-R2luRxHA3GSKgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-07-03 11:26:50
(4 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 21:04:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 17:03:58.901859 2026] [security2:error] [pid 19174:tid 19174] [client 2a0b:f4c2::15:23734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.belgiophar.org"] [uri "/.git/config"] [unique_id "aisivtzio4fr9cdsSaSzYgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Savvii
2026-06-10 08:37:44
(1 month ago)
20 attempts against mh-misbehave-ban on web-new
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 20:08:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 16:08:40.824151 2026] [security2:error] [pid 27900:tid 27900] [client 2a0b:f4c2::15:56684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.ndezrojo.com"] [uri "/.git/config"] [unique_id "aiMsyCPSp-PChbUv0iCu7QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 12:04:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 08:03:55.185641 2026] [security2:error] [pid 25080:tid 25080] [client 2a0b:f4c2::15:15678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.lamanchaorchards.com"] [uri "/.git/config"] [unique_id "aiK7K5Sb3s-gIhivGEElZwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-05-10 07:55:58
(2 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::15; scenario=http:scan; verdict=valid_ban; confidence=0.92; ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::15; scenario=http:scan; verdict=valid_ban; confidence=0.92; categories=14,15,18,22; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high
show less
Port Scan
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-09 14:11:41
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 10:11:32.225836 2026] [security2:error] [pid 31532:tid 31532] [client 2a0b:f4c2::15:7018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/ca.sql"] [unique_id "af9AlIMMeTX3U054-aIYTwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-05-05 12:12:00
(2 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-05-04 19:40:13
(2 months ago)
Blocked by UFW (TCP on 8333)
Source port: 46436
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 46436
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0015) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-04-30 10:43:15
(3 months ago)
Blocked by UFW (TCP on 33234)
Source port: 9002
Packet length: 120
This report (for 2a0b:f4c2:0000: ...
show more
Blocked by UFW (TCP on 33234)
Source port: 9002
Packet length: 120
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0015) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-30 09:31:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 05:31:42.652827 2026] [security2:error] [pid 12186:tid 12214] [client 2a0b:f4c2::15:63596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "la.productions"] [uri "/wp-config.phpc"] [unique_id "afMhfnckChmdMCDPe2rHWAAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:04:34
(3 months ago)
2026-04-26 08:00:54,229 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::15
2026-04-26 1 ...
show more
2026-04-26 08:00:54,229 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::15
2026-04-26 12:01:42,011 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::15
2026-04-26 18:01:39,675 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::15
2026-04-26 21:01:38,921 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::15
2026-04-27 00:04:29,975 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::15
show less
Brute-Force
๐บ๐ธ
ipblock.com
2026-04-21 12:26:00
(3 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack