πΉπ·
neron
2026-07-26 19:50:51
(4 hours ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
Anonymous
2026-07-26 08:20:04
(16 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
πΉπ·
neron
2026-07-24 15:30:03
(2 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΊπΈ
xmission.com
2026-07-22 21:33:52
(4 days ago)
Blocked by UFW (TCP on 8333)
Source port: 11102
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 11102
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0002) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-07-12 16:16:06
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210350) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 12:15:59.143568 2026] [security2:error] [pid 31070:tid 31070] [client 2a0b:f4c2::2:65366] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.trasimeno.ws|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.trasimeno.ws"] [uri "/isola_maggiore_it.html"] [unique_id "alO9vwp5CD8RVFB6ojes4AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-19 17:02:56
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 13:02:48.293718 2026] [security2:error] [pid 17819:tid 17819] [client 2a0b:f4c2::2:6454] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||astglobalgroup.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "astglobalgroup.com"] [uri "/db_globalgroup.sql"] [unique_id "ajV2OLnMW8_G4XE7xQhl-QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
HandyTreff.de
2026-05-15 12:22:14
(2 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -30.543 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -30.543 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Mobile Sa
show less
Web App Attack
Bad Web Bot
πΊπΈ
ipblock.com
2026-05-10 11:38:00
(2 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-06 19:32:24
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 15:32:17.051006 2026] [security2:error] [pid 17815:tid 17815] [client 2a0b:f4c2::2:8136] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||faithlines.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "faithlines.com"] [uri "/.sql"] [unique_id "afuXQZZ5xPJGOoRI-DzRygAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-28 15:30:25
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 11:30:20.164741 2026] [security2:error] [pid 23702:tid 23721] [client 2a0b:f4c2::2:63040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cheqs.org"] [uri "/wp-config.phpOLD"] [unique_id "afDSjAQXXyoq42Tk345OogAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-27 08:11:48
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 04:11:40.313981 2026] [security2:error] [pid 31689:tid 31707] [client 2a0b:f4c2::2:39552] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ceol.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ceol.com"] [uri "/ceo.sql"] [unique_id "ae8aPK88ut9lQ7UFnF9wMwAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:04:30
(3 months ago)
2026-04-26 08:00:53,327 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::2
2026-04-26 12 ...
show more
2026-04-26 08:00:53,327 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::2
2026-04-26 12:01:41,496 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::2
2026-04-26 18:01:39,150 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::2
2026-04-26 21:01:38,399 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::2
2026-04-27 00:04:24,429 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::2
show less
Brute-Force
π©πͺ
4server
2026-04-26 04:46:01
(3 months ago)
[SunApr2606:45:55.4294522026][security2:error][pid1633765:tid1634045][client2a0b:f4c2::2:0]ModSecuri ...
show more
[SunApr2606:45:55.4294522026][security2:error][pid1633765:tid1634045][client2a0b:f4c2::2:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"allegraravizza.it\"][uri\"/allegraraviz.sql\"][unique_id\"ae2YgzSUECaP_mVy_IM2FgAAAcE\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-18 18:48:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 14:48:06.677958 2026] [security2:error] [pid 3403813:tid 3403813] [client 2a0b:f4c2::2:35552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medusakenya.com"] [uri "/wp-config.phpbak"] [unique_id "aePR5rUK2REXBPO5jb4NHgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-16 22:03:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::2 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 18:02:58.793137 2026] [security2:error] [pid 3330573:tid 3330573] [client 2a0b:f4c2::2:41986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marv.us"] [uri "/wp-config.php.backup"] [unique_id "aeFckrYf-6_sOGlbEmgcdwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack