๐บ๐ธ
TPI-Abuse
2026-02-26 16:46:29
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 11:46:22.820158 2026] [security2:error] [pid 9212:tid 9212] [client 2a0b:f4c2::17:58676] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ouzcorp.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ouzcorp.com"] [uri "/dbuzcorp.sql"] [unique_id "aaB43tE4RcBPHeYVpMGVQAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 20:16:47
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 15:16:40.868549 2026] [security2:error] [pid 29088:tid 29088] [client 2a0b:f4c2::17:31196] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dwightbrown.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dwightbrown.com"] [uri "/own_db.sql"] [unique_id "aZy1qOAkNICTimgi7sQC1AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 13:24:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 08:24:12.317538 2026] [security2:error] [pid 8358:tid 8358] [client 2a0b:f4c2::17:15460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.bienvista.com"] [uri "/.git/config"] [unique_id "aZxU_LZ69JUu-8kNIezLugAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 16:50:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 11:50:38.543045 2026] [security2:error] [pid 2312:tid 2312] [client 2a0b:f4c2::17:53430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.avmarep.com"] [uri "/.git/config"] [unique_id "aZsz3mCF-BMVgAF_I6GybQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 16:34:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 11:34:38.558635 2026] [security2:error] [pid 25998:tid 25998] [client 2a0b:f4c2::17:15290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.genesis-one.com"] [uri "/.git/config"] [unique_id "aZswHtSguzAhu_XXBtTa7gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-02-22 06:04:57
(4 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::17; scenario=http:scan; verdict=valid_ban; confidence=0.90; ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::17; scenario=http:scan; verdict=valid_ban; confidence=0.90; categories=14,15,18; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scan/exploit pattern); Decision appears in active decisions total (2) and recent lookback window (2); No evidence of legitimate behavior or user activity
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-16 08:54:49
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 03:54:37.293770 2026] [security2:error] [pid 1621:tid 1621] [client 2a0b:f4c2::17:3288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||timetemple.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "timetemple.org"] [uri "/time.sql"] [unique_id "aZLbTeVNnDX1lE4_qSDW7QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 02:02:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 21:02:31.355653 2026] [security2:error] [pid 6070:tid 6070] [client 2a0b:f4c2::17:11890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.thebrotherhoodlounge.com"] [uri "/.git/config"] [unique_id "aYadN7xH8WifWeoS0hW8vwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2026-02-06 12:51:58
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.disabled
Timestamp: 2026-02-06T12:38:58Z
Ray ID: 9c9ab526be61e516
UA: python-requests/2.32.5
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-02 02:26:14
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 21:26:09.239453 2026] [security2:error] [pid 10651:tid 10651] [client 2a0b:f4c2::17:48462] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nextstepspersonalfinance.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nextstepspersonalfinance.com"] [uri "/nextstepspersonalfi.sql"] [unique_id "aYALQWY4frpadJR9UakDWwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-01-30 23:02:58
(5 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-29.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-26 02:36:46
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 21:36:40.764658 2026] [security2:error] [pid 30503:tid 30503] [client 2a0b:f4c2::17:10958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.lowrygroup.com"] [uri "/.git/config"] [unique_id "aXbTOEPiNMltQaMCmF2ezQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 01:04:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 20:04:27.168604 2026] [security2:error] [pid 1063860:tid 1063860] [client 2a0b:f4c2::17:38692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.truefauxstudio.com"] [uri "/.git/config"] [unique_id "aXa9m4XmkVbj_F_YUYGIyAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 12:51:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 07:51:10.975266 2026] [security2:error] [pid 30154:tid 30154] [client 2a0b:f4c2::17:22110] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||healingworksmassage.studio|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "healingworksmassage.studio"] [uri "/latest.sql"] [unique_id "aWo0PvczCmPkwO8eybwddAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-12 11:27:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::17 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 06:27:16.222903 2026] [security2:error] [pid 4751:tid 4780] [client 2a0b:f4c2::17:45466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.bhsclassof68.info"] [uri "/.git/config"] [unique_id "aWTalM9gHeSWRGi8fdHrGQAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack