πΊπΈ
xmission.com
2026-02-28 14:43:35
(6 months ago)
Blocked by UFW (TCP on 8333)
Source port: 13784
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 13784
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0029) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-02-26 16:47:04
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 11:46:28.282769 2026] [security2:error] [pid 7944:tid 7944] [client 2a0b:f4c2::29:52466] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ouzcorp.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ouzcorp.com"] [uri "/site.sql"] [unique_id "aaB45EnVdpiFSEcMNIIJMAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-26 01:09:41
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 20:09:32.349629 2026] [security2:error] [pid 22106:tid 22106] [client 2a0b:f4c2::29:33240] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||phoboschildren.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "phoboschildren.com"] [uri "/ldren_db.sql"] [unique_id "aZ-dTCvMx5bSRF5jhMouyAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
todix
2026-02-25 01:44:55
(6 months ago)
Web App Attack Exploid from 2a0b:f4c2::29
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-25 00:09:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 19:09:10.343280 2026] [security2:error] [pid 15139:tid 15139] [client 2a0b:f4c2::29:37140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.rogerproperties.com"] [uri "/.git/config"] [unique_id "aZ49pq9dUlXtGigVB6tFrgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-23 13:33:52
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 08:33:46.065050 2026] [security2:error] [pid 10683:tid 10683] [client 2a0b:f4c2::29:6484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||artspacecleveland.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "artspacecleveland.com"] [uri "/nd_wp1.sql"] [unique_id "aZxXOk7Yds5Rr3YeYPmStgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-22 07:53:54
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 02:53:48.326131 2026] [security2:error] [pid 19303:tid 19303] [client 2a0b:f4c2::29:5328] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||tracytappan.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tracytappan.net"] [uri "/back.sql"] [unique_id "aZq2DEwpIRtmfqpoXErWFwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ipblock.com
2026-02-22 00:42:00
(7 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-20 13:08:38
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 08:08:28.560444 2026] [security2:error] [pid 1588:tid 1614] [client 2a0b:f4c2::29:3678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tristatepropertymgmt.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tristatepropertymgmt.com"] [uri "/tristatepro.sql"] [unique_id "aZhczABohqf8rgtINnqtBQAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 01:10:06
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 20:10:00.418926 2026] [security2:error] [pid 19751:tid 19751] [client 2a0b:f4c2::29:3972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.banis-associates.com"] [uri "/.git/config"] [unique_id "aYqFaLJpXF2NeuPzQU-LigAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-02-02 22:59:09
(7 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-02-01.
show less
Hacking
Web App Attack
SSH
πΊπΈ
xmission.com
2026-01-31 14:54:16
(7 months ago)
Blocked by UFW (TCP on 8333)
Source port: 44680
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 44680
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0029) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-01-30 02:01:02
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 21:00:54.433476 2026] [security2:error] [pid 3521:tid 3521] [client 2a0b:f4c2::29:34846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||solporpoise.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "solporpoise.com"] [uri "/ise_com.sql"] [unique_id "aXwQ1uyPeEaFGfVCNd-bBAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-26 02:54:07
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 21:54:03.494493 2026] [security2:error] [pid 27139:tid 27139] [client 2a0b:f4c2::29:18090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.giantfern.com"] [uri "/.git/config"] [unique_id "aXbXSylaeMYZUvxik2v0UwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-25 20:25:53
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 15:25:46.799803 2026] [security2:error] [pid 12946:tid 12946] [client 2a0b:f4c2::29:43934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.neonmotel.com"] [uri "/.git/config"] [unique_id "aXZ8ShegLemMMRFexiIqHwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack