๐บ๐ธ
ipblock.com
2026-02-28 21:40:00
(7 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-21 14:58:43
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 09:58:39.067874 2026] [security2:error] [pid 4550:tid 4550] [client 2a0b:f4c2::20:30704] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vrevgaming.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vrevgaming.net"] [uri "/ming_com.sql"] [unique_id "aZnIHxJTYuS8QQLIDXodNAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
gnom4ik
2026-02-21 11:55:36
(7 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::20; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::20; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scan/exploit pattern); Decision appears in active decisions total count of 2; No evidence of legitimate behavior or high-volume normal traffic
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-16 08:54:43
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 03:54:28.631526 2026] [security2:error] [pid 15792:tid 15792] [client 2a0b:f4c2::20:30516] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||timetemple.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "timetemple.org"] [uri "/back.sql"] [unique_id "aZLbRDrKfqzU9uSwyhYsrwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-02-15 04:26:24
(7 months ago)
Blocked by UFW (TCP on 8333)
Source port: 12346
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 12346
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0020) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
pduggusa
2026-02-11 01:54:02
(7 months ago)
Detected attacking dugganusa.com at 2026-02-11T01:54:02.829Z | Source: DugganUSA PreCog auto-block
Hacking
๐บ๐ธ
pduggusa
2026-02-11 01:10:32
(7 months ago)
Detected attacking dugganusa.com at 2026-02-11T01:10:32.521Z | Source: DugganUSA PreCog auto-block
Hacking
๐บ๐ธ
pduggusa
2026-02-11 00:16:52
(7 months ago)
Detected attacking dugganusa.com at 2026-02-11T00:16:52.343Z | Source: DugganUSA PreCog auto-block
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-07 12:33:21
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 07:33:14.071928 2026] [security2:error] [pid 16686:tid 16686] [client 2a0b:f4c2::20:12626] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||braunhausmedia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "braunhausmedia.com"] [uri "/ausmedia_prod.sql"] [unique_id "aYcxCocB6wGm1v4GwvigqwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-01 22:59:18
(8 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-31.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-31 13:17:35
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 31 08:17:28.260666 2026] [security2:error] [pid 17199:tid 17199] [client 2a0b:f4c2::20:35376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williams-rodriguez.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williams-rodriguez.org"] [uri "/dump.sql"] [unique_id "aX4A6B6twnUoqDoOeZKlIAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 03:36:05
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 22:36:00.004087 2026] [security2:error] [pid 3979649:tid 3979649] [client 2a0b:f4c2::20:15754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.citati.net"] [uri "/.git/config"] [unique_id "aXbhIAoOOli3qQYiYYElrgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 00:26:54
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 19:26:51.863921 2026] [security2:error] [pid 2310:tid 2310] [client 2a0b:f4c2::20:32126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.mywhisperkids.com"] [uri "/.git/config"] [unique_id "aXa0yxlTHbEA0tkeiKSXMAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-25 23:48:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 18:48:13.207939 2026] [security2:error] [pid 1769:tid 1769] [client 2a0b:f4c2::20:11530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.essentialee.com"] [uri "/.git/config"] [unique_id "aXarvfL0DQWB2niS737FSgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-25 22:38:19
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 17:38:16.140464 2026] [security2:error] [pid 635925:tid 635925] [client 2a0b:f4c2::20:21316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.ourodyssey.us"] [uri "/.git/config"] [unique_id "aXabWLUlhYkqO3Gkmr5iTQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack