๐บ๐ธ
TPI-Abuse
2026-08-29 23:35:34
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 19:35:28.591348 2026] [security2:error] [pid 1529269:tid 1529363] [client 2a0b:f4c2:::7922] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.seips.org|F|2"] [data ".sassnet.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.seips.org"] [uri "/www.sassnet.com"] [unique_id "apNswBrw4yIIQMokubiCugAAAAE"], referer: https://www.seips.org/links.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-08-09 02:29:21
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-07 20:29:21
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-06 02:29:43
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-05 02:29:42
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-04 02:29:42
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ณ๐ฑ
MacLotsen
2026-08-02 19:10:12
(1 month ago)
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:01 +0200] "POST /wp-login.php HTTP/1.1" 200 3 ...
show more
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:01 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl/wp-login.php" "Mozilla/5.0 (Linux; Android 12; motorola edge 20) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Mobile Safari/537.36"
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:03 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl/wp-login.php" "Mozilla/5.0 (Linux; Android 12; motorola edge 20) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Mobile Safari/537.36"
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:06 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl/wp-login.php" "Mozilla/5.0 (Linux; Android 12; motorola edge 20) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Mobile Safari/537.36"
berlin01.tor-exit.artikel10.org - - [02/Aug/2026:21:09:08 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl/wp-login.php" "Mozilla/5.0 (Linux; Android 12; motorola edge 20) Ap
...
show less
Web App Attack
Brute-Force
๐บ๐ธ
xmission.com
2026-07-23 01:50:50
(1 month ago)
Blocked by UFW (TCP on 8333)
Source port: 5946
Packet length: 80
This report (for 2a0b:f4c2:0000:00 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 5946
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0000) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-07-08 19:28:34
(2 months ago)
Blocked by UFW (TCP on 8333)
Source port: 55196
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 55196
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0000) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-21 00:19:45
(2 months ago)
(mod_security) mod_security (id:211220) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:211220) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 20:19:34.455157 2026] [security2:error] [pid 5561:tid 5561] [client 2a0b:f4c2:::34784] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<\\\\?(?!xml\\\\s)" at ARGS:vars[0]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "70"] [id "211220"] [rev "4"] [msg "COMODO WAF: PHP Injection Attack||canaldumidi360.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canaldumidi360.com"] [uri "/index.php"] [unique_id "ajcuFmmmR8SXmgmOLSVPRwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-06-20 00:17:23
(2 months ago)
Blocked by UFW (TCP on 8333)
Source port: 53332
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 53332
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0000) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-06-13 09:31:59
(3 months ago)
Blocked by UFW (TCP on 8333)
Source port: 11364
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 11364
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0000) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-07 05:41:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 01:41:30.257636 2026] [security2:error] [pid 25233:tid 25233] [client 2a0b:f4c2:::36904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.dynarol.com"] [uri "/.git/config"] [unique_id "aiUEikGRjvh46C7Lgo_cPwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 14:47:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:47:31.272815 2026] [security2:error] [pid 12622:tid 12622] [client 2a0b:f4c2:::2628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.kochcreative.com"] [uri "/.git/config"] [unique_id "aiLhg0vbx2GbnWKCoJvbAwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 09:59:54
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:: (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 05:59:45.882506 2026] [security2:error] [pid 7752:tid 7752] [client 2a0b:f4c2:::53206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoincasting.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoincasting.com"] [uri "/bitcoincast.sql"] [unique_id "af20EdfXCGzTCU_QH8FdGQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack