๐บ๐ธ
TPI-Abuse
2025-11-10 19:51:21
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 14:51:12.108727 2025] [security2:error] [pid 9390:tid 9390] [client 2a0b:f4c2::4:27956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mhsalumnifoundation.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mhsalumnifoundation.org"] [uri "/mnifoundation.sql"] [unique_id "aRJCMMzUMb0crtGH_OMxtQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-05 16:39:03
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 05 11:38:57.026711 2025] [security2:error] [pid 15138:tid 15169] [client 2a0b:f4c2::4:2156] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.howlerrock.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.howlerrock.com"] [uri "/wordpress.sql"] [unique_id "aQt9oQa4uwSdMJrZcOvY9gAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-31 01:15:39
(7 months ago)
(db_admin_scan) srv103 DB admin scan 2a0b:f4c2::4 (Unknown): 1 in the last 3600 secs; Ports: *; Dire ...
show more
(db_admin_scan) srv103 DB admin scan 2a0b:f4c2::4 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-26 03:49:38
(7 months ago)
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::4 (Unknown): 1 in the last 3600 secs; Ports: *; Dire ...
show more
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::4 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-21 07:01:54
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 21 03:01:47.770741 2025] [security2:error] [pid 6905:tid 6927] [client 2a0b:f4c2::4:22478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.landmarkocchealth.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.landmarkocchealth.com"] [uri "/landmarkoccheal.sql"] [unique_id "aPcv2_DPNWILyZjtF2suggAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
oh.mg
2025-10-16 08:54:57
(7 months ago)
[Thu Oct 16 10:54:55.172652 2025] [security2:error] [pid 1446435:tid 1446444] [client 2a0b:f4c2::4:5 ...
show more
[Thu Oct 16 10:54:55.172652 2025] [security2:error] [pid 1446435:tid 1446444] [client 2a0b:f4c2::4:57578] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mmn.cat"] [uri "/backups.sql"] [unique_id "aPCy3-ya2ZrJP_lq0s7ACQAAAEc"]
[Thu Oct 16 10:54:57.093555 2025] [security2:error] [pid 1446435:tid 1446461] [client 2a0b:f4c2::4:57580] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "ano
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-06 12:51:19
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 06 08:51:11.084977 2025] [security2:error] [pid 16874:tid 16874] [client 2a0b:f4c2::4:41134] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aandbnaturalfoods.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aandbnaturalfoods.com"] [uri "/alfoods.sql"] [unique_id "aOO7Pw4y6MGAqq-mJP2f5AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-10-05 12:39:09
(8 months ago)
Blocked by UFW (TCP on 57524)
Source port: 9004
Packet length: 608
This report (for 2a0b:f4c2:0000: ...
show more
Blocked by UFW (TCP on 57524)
Source port: 9004
Packet length: 608
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-10-04 13:51:01
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 09:50:55.139702 2025] [security2:error] [pid 26052:tid 26052] [client 2a0b:f4c2::4:30702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mobileonlinecasinos.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mobileonlinecasinos.co"] [uri "/ileonlinecasinos.sql"] [unique_id "aOEmP3tABQrX08d0b6KHxwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-04 07:16:08
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 03:16:01.115124 2025] [security2:error] [pid 18615:tid 18615] [client 2a0b:f4c2::4:58576] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thefitzgeralds.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thefitzgeralds.org"] [uri "/thefi.sql"] [unique_id "aODJsUUS2zYQPaGaZjmFJAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-03 09:41:47
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 03 05:40:02.751839 2025] [security2:error] [pid 21156:tid 21156] [client 2a0b:f4c2::4:53486] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.theamarals.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.theamarals.com"] [uri "/arals.sql"] [unique_id "aN-Z8uIwkTviWfbbLl3AYgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-02 11:26:53
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 07:26:49.919086 2025] [security2:error] [pid 5866:tid 5866] [client 2a0b:f4c2::4:10990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eran.construction|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eran.construction"] [uri "/n.sql"] [unique_id "aN5heeRCY97rc180HqGpYgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-30 03:29:22
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 23:29:12.993087 2025] [security2:error] [pid 7846:tid 7846] [client 2a0b:f4c2::4:10048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.visionremota.info|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.visionremota.info"] [uri "/cdn1.sql"] [unique_id "aNtOiE5gsuRb-03pOrSwtwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-09-30 02:30:18
(8 months ago)
Blocked by UFW (TCP on 8333)
Source port: 61358
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 61358
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0004) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-09-27 14:02:26
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 27 10:02:19.682379 2025] [security2:error] [pid 2816:tid 2816] [client 2a0b:f4c2::4:4810] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||modestosoftwater.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "modestosoftwater.com"] [uri "/m.sql"] [unique_id "aNfua6V8Pw5WPD5-SUrf7gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack