๐ณ๐ฑ
Mangelot Hosting
2025-11-12 11:21:16
(10 months ago)
(modsecurity) srv103 ModSecurity 2a0b:f4c2::15 (Unknown): 5 in the last 3600 secs; Ports: *; Directi ...
show more
(modsecurity) srv103 ModSecurity 2a0b:f4c2::15 (Unknown): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 10:49:37
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 05:49:30.224652 2025] [security2:error] [pid 7584:tid 7584] [client 2a0b:f4c2::15:40644] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fundingangelinvestors.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fundingangelinvestors.com"] [uri "/fu.sql"] [unique_id "aRRmOt_nryEqB1SXJlZ1IwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
RtheCompany.eu
2025-11-12 09:05:00
(10 months ago)
Auto block
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-12 02:52:35
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 21:52:28.902988 2025] [security2:error] [pid 25472:tid 25472] [client 2a0b:f4c2::15:49402] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||investorscalifornia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "investorscalifornia.com"] [uri "/investors.sql"] [unique_id "aRP2bHZwmqY8kMTeIDpMHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 19:27:48
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 14:27:38.376035 2025] [security2:error] [pid 29541:tid 29541] [client 2a0b:f4c2::15:11286] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lockdownclaim.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lockdownclaim.com"] [uri "/lockdownclai.sql"] [unique_id "aROOKoJyqu8Z3ajZU0qvxAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Globe2
2025-11-05 14:57:16
(10 months ago)
ModSec - Multiple 403s within a short period of time
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-05 04:02:09
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 04 23:02:06.137250 2025] [security2:error] [pid 29216:tid 29216] [client 2a0b:f4c2::15:26736] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||silalaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "silalaw.com"] [uri "/.sql"] [unique_id "aQrMPmA_N0EwlST3rY9OqQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-04 06:18:28
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 04 01:18:22.697860 2025] [security2:error] [pid 1514:tid 1514] [client 2a0b:f4c2::15:54154] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gacstoday.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gacstoday.com"] [uri "/gacstoday.sql"] [unique_id "aQmarkrCw2PP2E1nmkXsxQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-31 01:56:40
(10 months ago)
(db_admin_scan) srv103 DB admin scan 2a0b:f4c2::15 (Unknown): 1 in the last 3600 secs; Ports: *; Dir ...
show more
(db_admin_scan) srv103 DB admin scan 2a0b:f4c2::15 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-30 18:51:46
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 14:51:40.571329 2025] [security2:error] [pid 28265:tid 28265] [client 2a0b:f4c2::15:59910] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ilovecoffeegroup.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ilovecoffeegroup.com"] [uri "/ilovecoffeegroup.sql"] [unique_id "aQOzvCVN713o9qmXwVGWlAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-26 04:32:46
(11 months ago)
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::15 (Unknown): 1 in the last 3600 secs; Ports: *; Dir ...
show more
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::15 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-25 20:56:41
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 25 16:56:33.914721 2025] [security2:error] [pid 21165:tid 21165] [client 2a0b:f4c2::15:39006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oogeothermal.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oogeothermal.com"] [uri "/geothermal.sql"] [unique_id "aP05gTJpeml4Hm0tW71nsAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-17 01:27:42
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 21:27:37.968381 2025] [security2:error] [pid 20817:tid 20817] [client 2a0b:f4c2::15:5250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mavikalem.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mavikalem.org"] [uri "/alem.sql"] [unique_id "aPGbiai_4qTg75UN0fSMrgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-16 00:02:32
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::15 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 15 20:02:24.095373 2025] [security2:error] [pid 30909:tid 30909] [client 2a0b:f4c2::15:28450] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||trunutraceuticals.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "trunutraceuticals.com"] [uri "/trun.sql"] [unique_id "aPA2EE1Ty1rHVZRD6Z0KbQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-10-08 21:11:49
(11 months ago)
Blocked by UFW (TCP on 8333)
Source port: 19404
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 19404
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0015) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan