๐บ๐ธ
TPI-Abuse
2026-02-23 10:26:24
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 05:26:17.161063 2026] [security2:error] [pid 15146:tid 15146] [client 2a0b:f4c2::5:24586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.dismain.com"] [uri "/.git/config"] [unique_id "aZwrSYTdoek7BCbTGPaZXAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 13:26:57
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 08:26:53.566745 2026] [security2:error] [pid 10664:tid 10767] [client 2a0b:f4c2::5:41422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||reghay.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "reghay.com"] [uri "/regha.sql"] [unique_id "aZsEHUstOwzUzaOm5Yh1zAAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
gnom4ik
2026-02-21 10:12:26
(5 months ago)
ban-reviewer auto report; ip=2a0b:f4c2::5; scenario=http:scan; verdict=valid_ban; confidence=0.90; c ...
show more
ban-reviewer auto report; ip=2a0b:f4c2::5; scenario=http:scan; verdict=valid_ban; confidence=0.90; categories=14,15,18; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scenario: http:scan); IP has active decisions total of 2, indicating repeated abuse patterns; Decision duration of 7740 minutes suggests a significant threat window
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-10 02:21:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:21:45.477577 2026] [security2:error] [pid 28663:tid 28663] [client 2a0b:f4c2::5:19112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.coloradospartans.com"] [uri "/.git/config"] [unique_id "aYqWOSfCMbOfMkL-IXib5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-08 20:49:22
(5 months ago)
Blocking for trying to access an exploit file: /findreplace.php
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-06 20:26:53
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 15:26:49.130388 2026] [security2:error] [pid 18653:tid 18653] [client 2a0b:f4c2::5:2428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.bbproductionsonline.com"] [uri "/.git/config"] [unique_id "aYZOibBYZUp7NMJNiIRttgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2026-02-06 12:39:30
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
Protocol: HTTP/1.1 (GET method)
Endpoint: /config/.env
Timestamp: 2026-02-06T12:37:44Z
Ray ID: 9c9ab358bc27e52e
UA: python-requests/2.32.5
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-01-31 23:00:25
(5 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-30.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-31 13:17:25
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 31 08:17:19.945104 2026] [security2:error] [pid 16800:tid 16800] [client 2a0b:f4c2::5:35132] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williams-rodriguez.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williams-rodriguez.org"] [uri "/williams-.sql"] [unique_id "aX4A3xaGC5vdBYo844xzuQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-30 14:34:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 09:34:51.956569 2026] [security2:error] [pid 9659:tid 9659] [client 2a0b:f4c2::5:34966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayareahiphopforever.org"] [uri "/.env"] [unique_id "aXzBi8H7eCQg0MVka3gSLQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-28 22:05:08
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 28 17:05:00.273076 2026] [security2:error] [pid 31443:tid 31443] [client 2a0b:f4c2::5:2222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jaynawilliamsrealty.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jaynawilliamsrealty.com"] [uri "/.sql"] [unique_id "aXqIDHluFTAZTba0iFsglwAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 21:34:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 16:34:19.843233 2026] [security2:error] [pid 28303:tid 28303] [client 2a0b:f4c2::5:34670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.controlledautomationinc.com"] [uri "/.git/config"] [unique_id "aXfd23Z7pmMqjKvnZyKZlQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 09:28:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 04:28:34.807981 2026] [security2:error] [pid 23804:tid 23804] [client 2a0b:f4c2::5:27506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.teamsewusa.com"] [uri "/.git/config"] [unique_id "aXczwq2phLz9WfDUYS1rkgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 00:33:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::5 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 19:33:53.489085 2026] [security2:error] [pid 29996:tid 29996] [client 2a0b:f4c2::5:51994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.jackkerrart.com"] [uri "/.git/config"] [unique_id "aXa2cZkRNDYfL2zCD8uT3gAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-01-18 08:50:50
(6 months ago)
Blocked by UFW (TCP on 8333)
Source port: 47180
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 47180
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0005) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan