πΊπΈ
TPI-Abuse
2025-09-02 15:03:46
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 11:03:41.301768 2025] [security2:error] [pid 26113:tid 26113] [client 2a0b:f4c2::19:48334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||justicehoward.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "justicehoward.com"] [uri "/usticehoward.sql"] [unique_id "aLcHTR4ePRnV4SoKb_tOawAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-02 03:00:10
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 23:00:00.187865 2025] [security2:error] [pid 6293:tid 6293] [client 2a0b:f4c2::19:2072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitess.com"] [uri "/wp-config.php_bk.zip"] [unique_id "aLZdsNgrv0dXgpV589iL1wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2025-08-31 07:56:14
(11 months ago)
Blocked by UFW (TCP on 8333)
Source port: 65230
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 65230
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0019) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2025-08-30 20:26:58
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 30 16:26:55.861094 2025] [security2:error] [pid 2048:tid 2048] [client 2a0b:f4c2::19:33022] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.paguilar.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.paguilar.com"] [uri "/lar.sql"] [unique_id "aLNej3TucAuBDP9fnw18QQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-30 10:51:22
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 30 06:51:14.022007 2025] [security2:error] [pid 30027:tid 30027] [client 2a0b:f4c2::19:7838] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lemoulinavent.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lemoulinavent.org"] [uri "/lemoulinaven.sql"] [unique_id "aLLXoiP9az-rBRK0lzQ8yQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-29 15:09:40
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 29 11:09:32.797391 2025] [security2:error] [pid 10734:tid 10734] [client 2a0b:f4c2::19:58880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daos.org"] [uri "/wp-config.php3.zip"] [unique_id "aLHCrEHZkyMHDYcQKS1GBAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-27 18:33:09
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 27 14:33:00.786676 2025] [security2:error] [pid 30589:tid 30589] [client 2a0b:f4c2::19:57332] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||danielbrower.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danielbrower.com"] [uri "/lbrower.sql"] [unique_id "aK9PXMVntUFN6ZvHtgl3awAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-27 14:03:04
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 27 10:02:56.226530 2025] [security2:error] [pid 30530:tid 30530] [client 2a0b:f4c2::19:16806] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||visionremota.info|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "visionremota.info"] [uri "/daily.sql"] [unique_id "aK8QEKppj3NtBEFksKRRigAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-25 11:52:58
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 25 07:52:51.166726 2025] [security2:error] [pid 15871:tid 15871] [client 2a0b:f4c2::19:33402] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||michelehoop.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michelehoop.com"] [uri "/michelehoop.sql"] [unique_id "aKxOk5JGKJo8cj_cwoST2wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2025-08-24 17:00:33
(11 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-08-24 06:24:42
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 24 02:24:38.154444 2025] [security2:error] [pid 21751:tid 21751] [client 2a0b:f4c2::19:42052] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||67ronin.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "67ronin.com"] [uri "/backup_wp.sql"] [unique_id "aKqwJhyuUSU9HlpLmfnNiwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-23 06:22:40
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 23 02:22:36.769982 2025] [security2:error] [pid 29793:tid 29793] [client 2a0b:f4c2::19:24308] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||heavenly-creatures.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "heavenly-creatures.com"] [uri "/heavenly-cr.sql"] [unique_id "aKleLH19Zj5uz8r4VclpNQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-22 03:01:49
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 21 23:01:44.771731 2025] [security2:error] [pid 1823:tid 1823] [client 2a0b:f4c2::19:36734] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||karenbernsteinlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "karenbernsteinlaw.com"] [uri "/karenberns.sql"] [unique_id "aKfdmIGpfjp_Vj9Gvr-j5gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-20 08:32:12
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 20 04:32:08.241802 2025] [security2:error] [pid 14598:tid 14598] [client 2a0b:f4c2::19:57036] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rebelhollowfarm.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rebelhollowfarm.com"] [uri "/wfarm.sql"] [unique_id "aKWICODzQGU-L-lSNLilfQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-20 07:01:06
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 20 03:00:59.491320 2025] [security2:error] [pid 7468:tid 7468] [client 2a0b:f4c2::19:5008] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||doctorbalog.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "doctorbalog.com"] [uri "/alog_com.sql"] [unique_id "aKVyq03blWH_ufW8b02LIgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack