๐ซ๐ฎ
gnom4ik
2026-02-22 07:27:14
(6 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::3; scenario=http:scan; verdict=valid_ban; confidence=0.85; c ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::3; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18,22; active_decisions=2; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'Port Scan' (category 14) in abuseipdb_context; IP flagged for 'Hacking' (category 15) in abuseipdb_context; IP flagged for 'Brute-Force' (category 18) in abuseipdb_context; IP flagged for 'SSH' (category 22) in abuseipdb_context; Decision w
show less
Port Scan
Hacking
Brute-Force
SSH
๐บ๐ธ
ipblock.com
2026-02-21 02:43:00
(6 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-02-20 11:18:47
(6 months ago)
Web App Attack - Exploid from 2a0b:f4c2::3
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 23:26:44
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 18:26:39.656108 2026] [security2:error] [pid 1616094:tid 1616225] [client 2a0b:f4c2::3:39842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||teritemme.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teritemme.com"] [uri "/back.sql"] [unique_id "aZZKr_lNv42de8S-KkqEwwAAAlM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-16 14:06:51
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 09:06:47.133541 2026] [security2:error] [pid 22684:tid 22684] [client 2a0b:f4c2::3:48352] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thepotteriesmesilla.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thepotteriesmesilla.com"] [uri "/tteriesmesilla_com.sql"] [unique_id "aZMkd3lPE4FPRJSmKpA_VAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-01-31 22:59:14
(7 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-30.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-25 21:47:18
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 16:47:14.246099 2026] [security2:error] [pid 14584:tid 14584] [client 2a0b:f4c2::3:33142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.eventsetcinc.com"] [uri "/.git/config"] [unique_id "aXaPYuaLdN-dQVQIz_BmxgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-25 20:22:04
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 15:21:55.299480 2026] [security2:error] [pid 3690126:tid 3690126] [client 2a0b:f4c2::3:8742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.carolinapetportraits.com"] [uri "/.git/config"] [unique_id "aXZ7Y8gsx9cQQy0nkMlKUgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-21 22:08:52
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 17:08:47.387641 2026] [security2:error] [pid 487789:tid 487789] [client 2a0b:f4c2::3:32078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.cypraea.info"] [uri "/.git/config"] [unique_id "aXFOb-SDmm1Wwx9apTwdSAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-18 04:47:22
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 23:47:15.792265 2026] [security2:error] [pid 1178451:tid 1178555] [client 2a0b:f4c2::3:61154] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lancasterdesignercraftsmen.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lancasterdesignercraftsmen.org"] [uri "/smen_com.sql"] [unique_id "aWxl013M4XxCVSaNMYWWoAAAAgQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 16:55:31
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 11:55:27.663467 2026] [security2:error] [pid 5166:tid 5166] [client 2a0b:f4c2::3:24012] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teleplussolutions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teleplussolutions.com"] [uri "/eleplussolutions_com.sql"] [unique_id "aWptf8pZaAPVPCSide6FJwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-12 11:23:57
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 06:23:50.177389 2026] [security2:error] [pid 9786:tid 9884] [client 2a0b:f4c2::3:11452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.pizzadlux.com"] [uri "/.git/config"] [unique_id "aWTZxtljC5e-KvS_bX686gAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
adamblack
2026-01-09 13:16:57
(8 months ago)
Automated attempt to access SQL dump file (/tk_com.sql) at chtkmtk.com
Web App Attack
IoT Targeted
๐บ๐ธ
TPI-Abuse
2026-01-09 09:02:24
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 04:02:16.623425 2026] [security2:error] [pid 11209:tid 11209] [client 2a0b:f4c2::3:57274] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||californiacbcdelegation.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "californiacbcdelegation.com"] [uri "/californiacbcdelega.sql"] [unique_id "aWDEGNvLuGLz6HGP2oTWMQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 08:36:27
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 03:36:21.304010 2025] [security2:error] [pid 3328:tid 3328] [client 2a0b:f4c2::3:29566] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hsoftwaresystems.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hsoftwaresystems.net"] [uri "/hsoftwaresyst.sql"] [unique_id "aVTghWGKCemQKxqKYlQ5wAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack