๐ณ๐ฑ
homeshowdomain.nl
2026-02-02 23:00:12
(7 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-02-01.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-01 19:05:39
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 14:05:31.958118 2026] [security2:error] [pid 1296:tid 1296] [client 2a0b:f4c2::1:3858] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||michael-beasley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michael-beasley.com"] [uri "/michael.sql"] [unique_id "aX-j-1slFV0fY_vfL1FrbQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 06:55:03
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 01:54:57.849653 2026] [security2:error] [pid 3380:tid 3380] [client 2a0b:f4c2::1:60632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.tapiaqualityproducts.com"] [uri "/.git/config"] [unique_id "aXcPwSm8iSlssrOW6REACQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-25 20:45:52
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 15:45:47.146432 2026] [security2:error] [pid 13233:tid 13233] [client 2a0b:f4c2::1:59950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.rotorservice.com"] [uri "/.git/config"] [unique_id "aXaA--KRGr7i4LsqxlxTxwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-01-25 09:15:01
(7 months ago)
Blocked by UFW (TCP on 8333)
Source port: 13070
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 13070
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0001) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-01-22 04:39:39
(8 months ago)
Blocked by UFW (TCP on 8333)
Source port: 5294
Packet length: 80
This report (for 2a0b:f4c2:0000:00 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 5294
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0001) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-21 16:58:28
(8 months ago)
(mod_security) mod_security (id:217291) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:217291) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 11:58:22.697245 2026] [security2:error] [pid 8019:tid 8019] [client 2a0b:f4c2::1:26698] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\ntimestamp. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||bodeur.com|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cntimestamp: \\x0d\\x0atimestamp"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "bodeur.com"] [uri "/track/open"] [unique_id "aXEFrqXYZ7EDEjjYHzKhmAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-18 03:43:43
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 22:43:36.557591 2026] [security2:error] [pid 12299:tid 12299] [client 2a0b:f4c2::1:61498] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lockdownclaim.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lockdownclaim.com"] [uri "/lockdowncl.sql"] [unique_id "aWxW6EhmtPjmuEVTXEa0jwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 19:30:37
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 14:30:29.079955 2026] [security2:error] [pid 3773456:tid 3773463] [client 2a0b:f4c2::1:30026] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iacsb.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iacsb.com"] [uri "/iacsb_com.sql"] [unique_id "aWqR1QhE8Dw2auQP0aAC0AAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-09 09:01:39
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 04:01:34.918194 2026] [security2:error] [pid 11127:tid 11127] [client 2a0b:f4c2::1:40854] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||californiacbcdelegation.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "californiacbcdelegation.com"] [uri "/calif.sql"] [unique_id "aWDD7mV_wsV22MU9abGTjQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 17:00:44
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 12:00:36.573003 2026] [security2:error] [pid 2093:tid 2093] [client 2a0b:f4c2::1:31572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mhsalumnifoundation.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mhsalumnifoundation.org"] [uri "/mhsalumnifoundation_com.sql"] [unique_id "aV6RNGQrHPNdEsrn9xupnQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 18:15:22
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 13:15:15.829528 2026] [security2:error] [pid 1070:tid 1070] [client 2a0b:f4c2::1:2614] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||graciousholding.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "graciousholding.com"] [uri "/graciousho.sql"] [unique_id "aVa5s_zOlELPy5urGB6RrwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 08:27:48
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 03:27:42.150669 2026] [security2:error] [pid 20394:tid 20394] [client 2a0b:f4c2::1:51824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||yogawithbubba.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "yogawithbubba.com"] [uri "/awithbubba_com.sql"] [unique_id "aVYv_qkXtEzIE-LhiCkidQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 20:29:09
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 15:29:02.661284 2025] [security2:error] [pid 19024:tid 19024] [client 2a0b:f4c2::1:60390] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||armorcorp.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "armorcorp.com"] [uri "/armorco.sql"] [unique_id "aVLkjhvijEjM7g3O-BAMpwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-25 23:53:55
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::1 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 18:53:47.896563 2025] [security2:error] [pid 20579:tid 20579] [client 2a0b:f4c2::1:26054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||unionega.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "unionega.com"] [uri "/nega_com.sql"] [unique_id "aU3Oi8QKsZQ-HgCFOYZMlgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack