๐บ๐ธ
xmission.com
2026-05-13 10:00:03
(4 months ago)
Blocked by UFW (TCP on 8333)
Source port: 50740
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 50740
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0005) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-08 15:01:17
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 11:01:07.559250 2026] [security2:error] [pid 32468:tid 32468] [client 2a0b:f4c2::5:31698] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cosplayculture.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cosplayculture.com"] [uri "/cosplayculture_com.sql"] [unique_id "af36s-VSnCZlPdsZfCP_BgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 05:53:34
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 01:53:30.696681 2026] [security2:error] [pid 4345:tid 4345] [client 2a0b:f4c2::5:29458] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fishleadership.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fishleadership.org"] [uri "/fishleadership_com.sql"] [unique_id "af16Wm3oqsze1ui-zmFpNgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 10:23:02
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 06:22:54.751196 2026] [security2:error] [pid 15107:tid 15107] [client 2a0b:f4c2::5:58838] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/nexportimport_com.sql"] [unique_id "afxn_vsUmrMT6JGS48lutAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:04:31
(4 months ago)
2026-04-26 08:00:53,543 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::5
2026-04-26 12 ...
show more
2026-04-26 08:00:53,543 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::5
2026-04-26 12:01:41,615 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::5
2026-04-26 18:01:39,267 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::5
2026-04-26 21:01:38,519 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::5
2026-04-27 00:04:25,778 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::5
show less
Brute-Force
๐ฉ๐ช
4server
2026-04-26 04:45:47
(4 months ago)
[SunApr2606:45:40.4961652026][security2:error][pid1633779:tid1634105][client2a0b:f4c2::5:0]ModSecuri ...
show more
[SunApr2606:45:40.4961652026][security2:error][pid1633779:tid1634105][client2a0b:f4c2::5:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.allegraravizza.it\"][uri\"/dump.sql\"][unique_id\"ae2YdBWSXdiV7SVJ9T0vIwAAAEs\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 03:40:32
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 23:40:25.215342 2026] [security2:error] [pid 7300:tid 7300] [client 2a0b:f4c2::5:64950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||damgoodit.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "damgoodit.com"] [uri "/goodit_com.sql"] [unique_id "ae2JKVe5WAeMOeOGwRveOAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-25 20:35:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 16:35:01.284045 2026] [security2:error] [pid 9772:tid 9772] [client 2a0b:f4c2::5:9502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayareamustangs.com"] [uri "/wp-config.php.uk"] [unique_id "ae0ldUbk_SWi550wMqWp6wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-04-24 14:56:51
(4 months ago)
Blocked by UFW (TCP on 8333)
Source port: 3840
Packet length: 80
This report (for 2a0b:f4c2:0000:00 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 3840
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0005) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-22 20:17:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 16:17:12.476939 2026] [security2:error] [pid 1747700:tid 1747700] [client 2a0b:f4c2::5:23632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nuewines.com"] [uri "/wp-config.bak"] [unique_id "aeksyIzDAAxipqM-exdLigAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-04-15 19:14:13
(5 months ago)
Blocked by UFW (TCP on 8333)
Source port: 36080
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 36080
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0005) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐จ๐ญ
4server
2026-04-13 17:20:49
(5 months ago)
[MonApr1319:20:41.8944602026][security2:error][pid3129298:tid3129313][client2a0b:f4c2::5:0]ModSecuri ...
show more
[MonApr1319:20:41.8944602026][security2:error][pid3129298:tid3129313][client2a0b:f4c2::5:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\^/wp-content/plugins/[\^/] /\(readme\\\\\\\\.txt\|changelog\\\\\\\\.txt\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"359\"][id\"960828\"][msg\"WordPresspluginenumerationblocked\"][hostname\"mail.mondocaneticino.ch\"][uri\"/wp-content/plugins/\*\\\\\"\,\\\\\"/readme.txt\"][unique_id\"ad0l6R3K1LarSPWLGvAuWgAAAA0\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-12 17:04:28
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 13:04:23.386218 2026] [security2:error] [pid 800150:tid 800150] [client 2a0b:f4c2::5:22670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.dualspiralsystems.com"] [uri "/.git/config"] [unique_id "advQl14lg9R22n4r9I8mKwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 12:09:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 08:09:13.541599 2026] [security2:error] [pid 21367:tid 21367] [client 2a0b:f4c2::5:46282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.darkhorseyachting.com"] [uri "/.git/config"] [unique_id "acpn6QLFGUHFUvcV_Cob9AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 05:33:40
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 01:32:40.096469 2026] [security2:error] [pid 25969:tid 25969] [client 2a0b:f4c2::5:22052] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoinsubscribers.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoinsubscribers.com"] [uri "/bitcoins.sql"] [unique_id "acTE-ItmSsmSPhMqVUalbQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack