๐บ๐ธ
ipblock.com
2026-03-06 02:17:00
(4 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-03-01 07:08:44
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:140.0) Gecko/20100101 Firefox/140.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-24 09:28:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 04:28:43.568794 2026] [security2:error] [pid 2744:tid 2769] [client 2a0b:f4c2::23:7708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.layoverlocations.com"] [uri "/.git/config"] [unique_id "aZ1vS2b3yARs7fL7vRvl7QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 01:51:35
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 20:51:26.270240 2026] [security2:error] [pid 29636:tid 29636] [client 2a0b:f4c2::23:52792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jpwatters.info.jpwatters.net"] [uri "/.git/config"] [unique_id "aZZsnrK0J2uYf1grQ-OtpAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 23:45:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 18:45:12.219426 2026] [security2:error] [pid 17677:tid 17677] [client 2a0b:f4c2::23:36048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.enlightened-workplace.com"] [uri "/.git/config"] [unique_id "aYZ9CF9O3qjlq_4aUlGNkwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2026-02-06 12:51:33
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
Protocol: HTTP/1.1 (GET method)
Endpoint: /status.json
Timestamp: 2026-02-06T12:48:32Z
Ray ID: 9c9ac32dacb89965
UA: python-requests/2.32.5
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-01-30 23:02:39
(6 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-29.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-28 22:04:24
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 28 17:04:17.977959 2026] [security2:error] [pid 29801:tid 29801] [client 2a0b:f4c2::23:1418] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jaynawilliamsrealty.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jaynawilliamsrealty.com"] [uri "/amsrealty_com.sql"] [unique_id "aXqH4aj6oDihNTZzZYyJ9wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 08:08:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 03:08:21.856710 2026] [security2:error] [pid 22997:tid 22997] [client 2a0b:f4c2::23:34502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.laecovillage.org"] [uri "/.git/config"] [unique_id "aXcg9fWInaLhPwRDhonQPgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 03:14:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 22:14:31.696687 2026] [security2:error] [pid 6335:tid 6335] [client 2a0b:f4c2::23:63644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.tarakanov.com"] [uri "/.git/config"] [unique_id "aXbcF3LHDBg47xk3qKCpsgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 14:35:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 09:35:00.111940 2026] [security2:error] [pid 24239:tid 24239] [client 2a0b:f4c2::23:19338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.e-ntourage.com"] [uri "/.git/config"] [unique_id "aWueFGbElmlfdBc5TgajMgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 18:05:37
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 13:05:30.907054 2026] [security2:error] [pid 1472972:tid 1472972] [client 2a0b:f4c2::23:25686] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thewhispertwins.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thewhispertwins.com"] [uri "/hewhispertwins_com.sql"] [unique_id "aWp96h1szxRrpxeRt2RgBgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 11:20:19
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 06:20:10.898462 2026] [security2:error] [pid 3396061:tid 3396076] [client 2a0b:f4c2::23:32836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||annacaird.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "annacaird.com"] [uri "/acaird_com.sql"] [unique_id "aWoe6o2TCMWLxU-X1qjz1AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 00:18:02
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 19:17:55.509826 2025] [security2:error] [pid 28516:tid 28516] [client 2a0b:f4c2::23:63146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hiddenmoosecorners.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hiddenmoosecorners.com"] [uri "/orners.sql"] [unique_id "aVRrs6UIfbVtuKATVGFTrAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-30 07:45:59
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::23 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 02:45:51.846364 2025] [security2:error] [pid 16800:tid 16800] [client 2a0b:f4c2::23:29374] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||konahawaiirealty.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "konahawaiirealty.com"] [uri "/konahawaiirea.sql"] [unique_id "aVODL9QwsZOBIg9YoFQB1gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack