Anonymous
2026-04-26 21:04:38
(4 months ago)
2026-04-26 08:00:55,407 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::31
2026-04-26 1 ...
show more
2026-04-26 08:00:55,407 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::31
2026-04-26 12:01:42,672 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::31
2026-04-26 18:01:40,319 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::31
2026-04-26 21:01:39,584 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::31
2026-04-27 00:04:34,463 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::31
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-04-25 04:51:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 00:51:39.310614 2026] [security2:error] [pid 16869:tid 16869] [client 2a0b:f4c2::31:46814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soonerstone.com"] [uri "/wp-config.php.us"] [unique_id "aexIW1XGKx2V-o_X2A0jXQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ipblock.com
2026-04-20 15:20:00
(4 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-19 06:48:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 02:48:12.924096 2026] [security2:error] [pid 1666928:tid 1666928] [client 2a0b:f4c2::31:22012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starsmogsandiego.com"] [uri "/wp-config.php.uk"] [unique_id "aeR6rAkxD9xOCK62-HiswwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-15 11:22:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 07:22:33.713772 2026] [security2:error] [pid 2832102:tid 2832102] [client 2a0b:f4c2::31:31288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idahostem.org"] [uri "/wp-config.phpbak"] [unique_id "ad90-XzXGhJCrnEf1EYjZgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-04-09 11:57:31
(5 months ago)
Blocked by UFW (TCP on 8333)
Source port: 5870
Packet length: 80
This report (for 2a0b:f4c2:0000:00 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 5870
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0031) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
ipblock.com
2026-03-31 17:18:00
(5 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 14:42:36
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 10:42:28.871859 2026] [security2:error] [pid 28171:tid 28171] [client 2a0b:f4c2::31:23658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.taxgroupsd.com"] [uri "/.git/config"] [unique_id "acvdVOSSOXlBUQaVGdQlBgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ipblock.com
2026-03-21 15:03:00
(5 months ago)
IPBlock protected site ID [4055-d][s=03].
Rogue crawler, does not respect robots.txt
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-03-09 04:14:11
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 00:14:05.628005 2026] [security2:error] [pid 27545:tid 27545] [client 2a0b:f4c2::31:35334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||geckoturner.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "geckoturner.com"] [uri "/r_wp1.sql"] [unique_id "aa5JDcB2oWO1qPk4e9MbEQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-09 01:41:01
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 21:40:56.240295 2026] [security2:error] [pid 28511:tid 28511] [client 2a0b:f4c2::31:57430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mobileonlinecasinos.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mobileonlinecasinos.co"] [uri "/bileonlinecasinos_prod.sql"] [unique_id "aa4lKIU_21ywcnH0meWPFgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-04 13:55:09
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 08:54:58.250363 2026] [security2:error] [pid 29219:tid 29219] [client 2a0b:f4c2::31:47132] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||forerunnersjazz.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "forerunnersjazz.org"] [uri "/rsjazz_db.sql"] [unique_id "aag5snU7QcJWS-tmS-ZuoAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-26 05:39:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 00:39:34.481108 2026] [security2:error] [pid 10636:tid 10636] [client 2a0b:f4c2::31:42760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.eliteelectricalservices.us"] [uri "/.git/config"] [unique_id "aZ_clrChjeqqF2_QR08H7wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
todix
2026-02-25 01:44:39
(6 months ago)
Web App Attack Exploid from 2a0b:f4c2::31
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-23 07:24:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::31 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 02:24:16.340069 2026] [security2:error] [pid 28953:tid 28953] [client 2a0b:f4c2::31:45094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.lonescouting.us"] [uri "/.git/config"] [unique_id "aZwAoCs73g8WeS0LxLMVDQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack