๐บ๐ธ
TPI-Abuse
2026-05-08 22:09:25
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 18:09:21.015542 2026] [security2:error] [pid 2422:tid 2422] [client 2a0b:f4c2::9:10034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hotelausland.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hotelausland.com"] [uri "/ho.sql"] [unique_id "af5fEWe1lD3SMGT0VCrXwgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 09:02:15
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 05:02:09.198023 2026] [security2:error] [pid 16038:tid 16038] [client 2a0b:f4c2::9:64614] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||customhumanrobots.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "customhumanrobots.com"] [uri "/customh.sql"] [unique_id "af2mkcqTzQHbE9CnV2eoBwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 05:53:21
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 01:53:13.812284 2026] [security2:error] [pid 32045:tid 32045] [client 2a0b:f4c2::9:30530] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fishleadership.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fishleadership.org"] [uri "/fishle.sql"] [unique_id "af16SVkiRmZgSxCO57indwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-04-30 11:07:40
(4 months ago)
Blocked by UFW (TCP on 60958)
Source port: 9002
Packet length: 120
This report (for 2a0b:f4c2:0000: ...
show more
Blocked by UFW (TCP on 60958)
Source port: 9002
Packet length: 120
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0009) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-04-28 09:13:56
(4 months ago)
Blocked by UFW (TCP on 8333)
Source port: 43108
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 43108
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0009) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-04-26 21:04:32
(4 months ago)
2026-04-26 08:00:53,830 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::9
2026-04-26 12 ...
show more
2026-04-26 08:00:53,830 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::9
2026-04-26 12:01:41,772 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::9
2026-04-26 18:01:39,429 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::9
2026-04-26 21:01:38,678 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::9
2026-04-27 00:04:27,394 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0b:f4c2::9
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-14 13:05:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 09:05:32.499198 2026] [security2:error] [pid 3674413:tid 3674413] [client 2a0b:f4c2::9:30452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "admiralpointe.com"] [uri "/wp-config.php.com"] [unique_id "ad47nMw8cRJRb9kfjhM-bgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-04-11 03:16:43
(5 months ago)
Blocked by UFW (TCP on 8333)
Source port: 45994
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 45994
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0009) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-08 05:52:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 01:51:56.378274 2026] [security2:error] [pid 1953753:tid 1953753] [client 2a0b:f4c2::9:57574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healingworksmassage.studio"] [uri "/wp-config.phpr"] [unique_id "adXs_JXIW0A7i9k0KR5GvgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 19:39:50
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 15:39:41.202388 2026] [security2:error] [pid 12241:tid 12261] [client 2a0b:f4c2::9:6076] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||datuinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "datuinc.com"] [uri "/backupdb.sql"] [unique_id "ac7F_Y1D_VpHQqsQmv3SsQAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 03:53:26
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 23:53:17.425381 2026] [security2:error] [pid 26039:tid 26039] [client 2a0b:f4c2::9:44006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||atmoorehealthcare.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "atmoorehealthcare.com"] [uri "/atmoorehe.sql"] [unique_id "ac3oLUeUtVT0Gu-vV3R_zwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 18:13:43
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 14:13:32.015714 2026] [security2:error] [pid 19641:tid 19641] [client 2a0b:f4c2::9:29198] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rebelhollowfarm.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rebelhollowfarm.com"] [uri "/lowfarm_com.sql"] [unique_id "acAxTLH8FMXl2ZRm_dYIMQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-10 04:52:35
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 00:52:30.099434 2026] [security2:error] [pid 18869:tid 18869] [client 2a0b:f4c2::9:41444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lkabookkeeping.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lkabookkeeping.com"] [uri "/ookkeeping_prod.sql"] [unique_id "aa-jjjDXK6lIXpcN_QmuhwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 04:14:23
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::9 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 00:14:14.717651 2026] [security2:error] [pid 25536:tid 25536] [client 2a0b:f4c2::9:12434] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||geckoturner.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "geckoturner.com"] [uri "/rner_db.sql"] [unique_id "aa5JFoc2yCCn17aMZqNLFAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-03-05 04:50:55
(6 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /berpsychologenpraktijk_prod.sql (Rule ID: 920440) - URL file extension is restricted by policy
show less
Web App Attack
SQL Injection
Hacking