๐บ๐ธ
TPI-Abuse
2025-10-10 07:31:54
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 10 03:31:49.033252 2025] [security2:error] [pid 6121:tid 6121] [client 2a0b:f4c2::20:61678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||convtek.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "convtek.com"] [uri "/wp.sql"] [unique_id "aOi2ZdKaK3CUUxBXdHOU5AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-08 04:34:37
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 08 00:34:29.813913 2025] [security2:error] [pid 21616:tid 21616] [client 2a0b:f4c2::20:26992] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stalbansparish.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stalbansparish.org"] [uri "/ish.sql"] [unique_id "aOXp1StNEM-dgZYqpohe0QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-06 10:12:47
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 06 06:12:40.412788 2025] [security2:error] [pid 4561:tid 4561] [client 2a0b:f4c2::20:37680] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||artbytracyjane.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "artbytracyjane.com"] [uri "/jane.sql"] [unique_id "aOOWGPNbKD9NQ6vSlyLWowAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-06 04:04:43
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 06 00:04:37.285769 2025] [security2:error] [pid 18403:tid 18403] [client 2a0b:f4c2::20:59824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||coolerboxes.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coolerboxes.com"] [uri "/rboxes.sql"] [unique_id "aOM_1YMdGh6ieGR_SdU1sQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-05 10:31:31
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 06:31:24.849349 2025] [security2:error] [pid 17244:tid 17247] [client 2a0b:f4c2::20:2100] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||conservativedemocrat.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "conservativedemocrat.com"] [uri "/conserv.sql"] [unique_id "aOJI_NjpzTjhok8MMLPjfQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-02 14:55:03
(11 months ago)
2a0b:f4c2::20 - - [02/Oct/2025:14:55:02 +0000] "GET /.env HTTP/1.1" 302 451 "-" "python-requests/2.3 ...
show more
2a0b:f4c2::20 - - [02/Oct/2025:14:55:02 +0000] "GET /.env HTTP/1.1" 302 451 "-" "python-requests/2.32.3"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-02 06:13:16
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 02:13:11.636000 2025] [security2:error] [pid 15176:tid 15176] [client 2a0b:f4c2::20:57786] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||toolsandtutorialsforwriters.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "toolsandtutorialsforwriters.com"] [uri "/toolsandtu.sql"] [unique_id "aN4X97Mc8M54G2Nvgk4-qAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
stinpriza
2025-10-01 18:45:56
(11 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
xmission.com
2025-10-01 10:56:44
(11 months ago)
Blocked by UFW (TCP on 8333)
Source port: 15738
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 15738
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0020) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-10-01 04:57:51
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 00:57:47.581426 2025] [security2:error] [pid 3122:tid 3135] [client 2a0b:f4c2::20:9430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arizonasolutionsgroup.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arizonasolutionsgroup.com"] [uri "/onsgroup.sql"] [unique_id "aNy0y_oqc-P2FgK-R4dh6gAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-30 16:02:24
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 30 12:02:17.360504 2025] [security2:error] [pid 2975:tid 2975] [client 2a0b:f4c2::20:53344] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||waterjetsolutions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "waterjetsolutions.com"] [uri "/waterjetso.sql"] [unique_id "aNv_Cd0Kpvj-bX3xUqUAUAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-30 00:22:48
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 20:22:40.757828 2025] [security2:error] [pid 17665:tid 17665] [client 2a0b:f4c2::20:39600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||twixmixy.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "twixmixy.com"] [uri "/wp.sql"] [unique_id "aNsi0L4ZQmYYymRS3u3vjgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-25 23:35:59
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 19:35:55.100219 2025] [security2:error] [pid 14390:tid 14390] [client 2a0b:f4c2::20:63274] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||primacomm.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "primacomm.com"] [uri "/daily.sql"] [unique_id "aNXR2ygPUmnHSs8PLOna9gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-25 04:39:31
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 00:39:24.592765 2025] [security2:error] [pid 25132:tid 25132] [client 2a0b:f4c2::20:39920] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||goseethenurse.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goseethenurse.com"] [uri "/gos.sql"] [unique_id "aNTHfBVso-uIm-MTPOAjBAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-24 21:35:12
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::20 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 17:35:08.306993 2025] [security2:error] [pid 5099:tid 5099] [client 2a0b:f4c2::20:53418] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lemoulinavent.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lemoulinavent.org"] [uri "/linavent.sql"] [unique_id "aNRkDP3ZxtpzNP44nIGXywAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack