๐จ๐ญ
Peter-Johann Sarbach
2026-07-28 03:46:57
(18 hours ago)
Jul 27 21:03:45 pop3-login: Info: Disconnected: Connection closed (no auth attempts in 1 secs): user ...
show more
Jul 27 21:03:45 pop3-login: Info: Disconnected: Connection closed (no auth attempts in 1 secs): user=<>, rip=2a0f:df00:0:255::203, lip=x.x.x.x, TLS, TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
show less
Hacking
๐บ๐ธ
xmission.com
2026-07-23 08:32:40
(5 days ago)
Blocked by UFW (TCP on 8333)
Source port: 21881
Packet length: 72
This report (for 2a0f:df00:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 21881
Packet length: 72
This report (for 2a0f:df00:0000:0255:0000:0000:0000:0203) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-07-12 15:20:32
(2 weeks ago)
Blocked by UFW (TCP on 44488)
Source port: 444
Packet length: 84
This report (for 2a0f:df00:0000:02 ...
show more
Blocked by UFW (TCP on 44488)
Source port: 444
Packet length: 84
This report (for 2a0f:df00:0000:0255:0000:0000:0000:0203) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฎ๐น
VHosting
2026-06-25 15:14:23
(1 month ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-19 17:02:35
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 13:02:27.686018 2026] [security2:error] [pid 20623:tid 20623] [client 2a0f:df00:0:255::203:50985] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||astglobalgroup.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "astglobalgroup.com"] [uri "/astglobalgroup_db.sql"] [unique_id "ajV2I7B5KfM6W-LOAIhzLgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 18:56:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:56:36.672581 2026] [security2:error] [pid 5597:tid 5597] [client 2a0f:df00:0:255::203:29153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.yacher.com"] [uri "/.git/config"] [unique_id "aicQZDYN6bhJGIYDJo_mZQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 12:31:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 08:31:04.249492 2026] [security2:error] [pid 21027:tid 21027] [client 2a0f:df00:0:255::203:13827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.sidegigfab.com"] [uri "/.git/config"] [unique_id "aia2CKyWpxZPztAMOl8jtQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 11:51:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 07:50:56.319147 2026] [security2:error] [pid 15338:tid 15338] [client 2a0f:df00:0:255::203:13187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.enzeder.com"] [uri "/.git/config"] [unique_id "aiK4IK7JcvswlmbAIK27uQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 11:26:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 07:26:26.897248 2026] [security2:error] [pid 24804:tid 24804] [client 2a0f:df00:0:255::203:12615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.flyingcardcompany.com"] [uri "/.git/config"] [unique_id "aiKyYncE0tV8U9eC2M7HPwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-05-28 06:43:00
(2 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 00:17:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 20:17:05.812071 2026] [security2:error] [pid 18536:tid 18536] [client 2a0f:df00:0:255::203:59693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mjkhan.com"] [uri "/wp-config.php.ca"] [unique_id "afFOAaElrQrPJF-SiSwczgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:05:28
(3 months ago)
2026-04-26 08:01:05,685 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0f:df00:0:255::203
2026- ...
show more
2026-04-26 08:01:05,685 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0f:df00:0:255::203
2026-04-26 12:01:49,380 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0f:df00:0:255::203
2026-04-26 18:01:46,930 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0f:df00:0:255::203
2026-04-26 21:01:46,270 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0f:df00:0:255::203
2026-04-27 00:05:26,707 fail2ban.actions [7718]: NOTICE [tor] Ban 2a0f:df00:0:255::203
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-22 10:40:16
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 06:40:05.807751 2026] [security2:error] [pid 23222:tid 23222] [client 2a0f:df00:0:255::203:54395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "technesa.com"] [uri "/wp-config.php.de"] [unique_id "aeilhU8YxdVciwwNx8O_lwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-04-15 19:11:56
(3 months ago)
[WedApr1521:11:50.4127052026][security2:error][pid1259108:tid1259113][client2a0f:df00:0:255::203:0]M ...
show more
[WedApr1521:11:50.4127052026][security2:error][pid1259108:tid1259113][client2a0f:df00:0:255::203:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\^/wp-content/plugins/[\^/] /\(readme\\\\\\\\.txt\|changelog\\\\\\\\.txt\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"359\"][id\"960828\"][msg\"WordPresspluginenumerationblocked\"][hostname\"tipicalonline.com\"][uri\"/wp-content/plugins/burst-statistics/readme.txt\"][unique_id\"ad_i9tKZ2eV_XMHh-YuUYAAAAMM\"]
show less
Hacking
Web App Attack
๐บ๐ธ
chronos
2026-04-06 06:37:33
(3 months ago)
[AUTORAVALT][[06/04/2026 - 03:37:32 -03:00 UTC]
Attack from [2a0f:df00:0:255::203] Action: BLocKed
...
show more
[AUTORAVALT][[06/04/2026 - 03:37:32 -03:00 UTC]
Attack from [2a0f:df00:0:255::203] Action: BLocKed
Phishing -> Phishing websites and/or email.
Email Spam -> Spam email content, infected attachments, and phishing emails.
Hacking... Unauthorized attempts to access the server.
Spoofing -> Email sender spoofing.
Brute-Force -> Credential brute-force attacks on web]
...
show less
Brute-Force
Email Spam
Spoofing
Phishing
Hacking