๐บ๐ธ
TPI-Abuse
2026-04-08 05:51:52
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 01:51:44.534864 2026] [security2:error] [pid 1950222:tid 1950222] [client 2a0b:f4c2::4:32150] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||healingworksmassage.studio|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "healingworksmassage.studio"] [uri "/bb-config.php.bak"] [unique_id "adXs8Dup7PQGDVqoBsmL2gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-04-04 14:01:31
(3 months ago)
Blocked by UFW (TCP on 8333)
Source port: 62040
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 62040
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-03-22 03:13:18
(4 months ago)
Blocked by UFW (TCP on 8333)
Source port: 51000
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 51000
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
ipblock.com
2026-03-18 06:04:00
(4 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 19:06:36
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 14:06:31.334664 2026] [security2:error] [pid 32703:tid 32703] [client 2a0b:f4c2::4:29930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||sekelconsulting.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sekelconsulting.com"] [uri "/elconsulting_wp1.sql"] [unique_id "aacxN27ysc7nDiHPJDcmCQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 16:46:37
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 11:46:29.670197 2026] [security2:error] [pid 11209:tid 11209] [client 2a0b:f4c2::4:56474] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ouzcorp.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ouzcorp.com"] [uri "/wordpress_p.sql"] [unique_id "aaB45ZNit21i3p8Mpp12dQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-25 11:56:37
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 06:56:30.043310 2026] [security2:error] [pid 7905:tid 7905] [client 2a0b:f4c2::4:56192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thesalonx.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thesalonx.com"] [uri "/onx_db.sql"] [unique_id "aZ7jbvdiUGXgX1efwDjYLQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 13:48:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 08:48:27.633928 2026] [security2:error] [pid 15674:tid 15696] [client 2a0b:f4c2::4:32960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.peimbert.com"] [uri "/.git/config"] [unique_id "aZ2sKwgFhPNdzsPCQDcdmwAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 03:36:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 22:36:32.628322 2026] [security2:error] [pid 19394:tid 19394] [client 2a0b:f4c2::4:9626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.brigittecavanagh.com"] [uri "/.git/config"] [unique_id "aZvLQFRD8OeIYLTGgYOitwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 19:06:07
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 14:06:03.989087 2026] [security2:error] [pid 25895:tid 25895] [client 2a0b:f4c2::4:56670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.creareformis.com"] [uri "/.git/config"] [unique_id "aZtTm1UN_B_XHpV1nNz3WQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-02-22 04:09:50
(5 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::4; scenario=http:scan; verdict=valid_ban; confidence=0.90; c ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::4; scenario=http:scan; verdict=valid_ban; confidence=0.90; categories=14,15,18,22; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scenario: http:scan); Appears in abuseipdb default categories for port scan (14), hacking (15), brute-force (18), and SSH (22); IP has active decisions total of 2, indicating repeated or ongoing suspicious behavior
show less
Port Scan
Hacking
Brute-Force
SSH
๐บ๐ธ
xmission.com
2026-02-08 09:32:53
(5 months ago)
Blocked by UFW (TCP on 8333)
Source port: 43786
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 43786
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-02-03 22:59:24
(5 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-02-02.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-26 07:28:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 02:28:04.546447 2026] [security2:error] [pid 4481:tid 4481] [client 2a0b:f4c2::4:36890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.krislajeskiedesign.com"] [uri "/.git/config"] [unique_id "aXcXhN81_4b_sgqdgIeuBAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-25 21:37:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 16:37:25.753582 2026] [security2:error] [pid 7495:tid 7495] [client 2a0b:f4c2::4:62684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.planettony.com"] [uri "/.git/config"] [unique_id "aXaNFfWSl37mwcxFucXR0wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack