π³π±
MacLotsen
2026-08-02 19:10:20
(2 weeks ago)
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:01 +0200] "POST /wp-login.php HTTP/1.1" 200 3 ...
show more
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:01 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl/wp-login.php" "Mozilla/5.0 (Linux; Android 12; motorola edge 20) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Mobile Safari/537.36"
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:03 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl/wp-login.php" "Mozilla/5.0 (Linux; Android 12; motorola edge 20) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Mobile Safari/537.36"
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:06 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl/wp-login.php" "Mozilla/5.0 (Linux; Android 12; motorola edge 20) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Mobile Safari/537.36"
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:08 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl/wp-login.php" "Mozilla/5.0 (Linux; Android 12; motorola edge 20) Ap
...
show less
Web App Attack
Brute-Force
πΊπΈ
xmission.com
2026-07-08 05:29:31
(1 month ago)
Blocked by UFW (TCP on 8333)
Source port: 22078
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 22078
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0006) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
xmission.com
2026-07-07 06:35:26
(1 month ago)
Blocked by UFW (TCP on 8333)
Source port: 45902
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 45902
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0006) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-06-12 00:59:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 20:59:20.240745 2026] [security2:error] [pid 2663:tid 2663] [client 2a0b:f4c2::6:15094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.concoursegallery.com"] [uri "/.git/config"] [unique_id "aitZ6F7azkOH1Fqroy3cYAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-06-02 13:05:28
(2 months ago)
Blocked by UFW (TCP on 8333)
Source port: 42080
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 42080
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0006) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-26 06:21:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 02:21:49.313034 2026] [security2:error] [pid 1120:tid 1120] [client 2a0b:f4c2::6:36794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.pattenden.com"] [uri "/.git/config"] [unique_id "ahU7_e7bdyxUdT3Rl8KoJQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-25 13:41:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 09:41:37.608050 2026] [security2:error] [pid 12107:tid 12107] [client 2a0b:f4c2::6:51342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barigby.com"] [uri "/.git/"] [unique_id "ahRRkXbtO0lKe0QHDVBxkwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-05-22 16:29:02
(3 months ago)
Blocked by UFW (TCP on 8333)
Source port: 19462
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 19462
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0006) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
ipblock.com
2026-05-17 13:38:00
(3 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-09 17:14:28
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 13:14:22.637222 2026] [security2:error] [pid 366:tid 366] [client 2a0b:f4c2::6:57906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jeremyscraig.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeremyscraig.com"] [uri "/je.sql"] [unique_id "af9rbl-UVFOGef8559kFeQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-08 22:09:18
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 18:09:11.573941 2026] [security2:error] [pid 19532:tid 19532] [client 2a0b:f4c2::6:46764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hotelausland.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hotelausland.com"] [uri "/latest.sql"] [unique_id "af5fB8ZfaBn4G5HW71soaQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-04-30 11:03:15
(3 months ago)
Blocked by UFW (TCP on 47682)
Source port: 9004
Packet length: 214
This report (for 2a0b:f4c2:0000: ...
show more
Blocked by UFW (TCP on 47682)
Source port: 9004
Packet length: 214
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0006) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-04-26 21:58:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 17:58:43.698761 2026] [security2:error] [pid 22008:tid 22008] [client 2a0b:f4c2::6:62490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theseventhcongregationofladderdayvixens.org"] [uri "/wp-config.bak"] [unique_id "ae6Kk8EDVBP3WdJUt3L_pQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:04:32
(3 months ago)
2026-04-26 08:00:53,615 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::6
2026-04-26 12 ...
show more
2026-04-26 08:00:53,615 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::6
2026-04-26 12:01:41,655 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::6
2026-04-26 18:01:39,308 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::6
2026-04-26 21:01:38,559 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::6
2026-04-27 00:04:26,152 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::6
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-04-26 20:03:21
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::6 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 16:03:15.656411 2026] [security2:error] [pid 5952:tid 5952] [client 2a0b:f4c2::6:2116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||internetnameregistration.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "internetnameregistration.com"] [uri "/inte.sql"] [unique_id "ae5vg41VR3lONsZn6d5u5QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack