πΊπΈ
xmission.com
2025-09-04 01:12:21
(1 year ago)
Blocked by UFW (TCP on 9999)
Source port: 49214
Packet length: 80
This report (for 2a0f:df00:0000:0 ...
show more
Blocked by UFW (TCP on 9999)
Source port: 49214
Packet length: 80
This report (for 2a0f:df00:0000:0255:0000:0000:0000:0203) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Ping of Death
Port Scan
πΊπΈ
TPI-Abuse
2025-09-03 05:10:58
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 03 01:10:50.665552 2025] [security2:error] [pid 28209:tid 28209] [client 2a0f:df00:0:255::203:43458] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kbalan.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kbalan.com"] [uri "/daily.sql"] [unique_id "aLfN2nN_gNnyW9wxEWLYjAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2025-09-02 00:45:48
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-08-31 20:05:57
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 16:05:51.225597 2025] [security2:error] [pid 14044:tid 14044] [client 2a0f:df00:0:255::203:35966] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||psychiatryabuse.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "psychiatryabuse.com"] [uri "/atryabuse.sql"] [unique_id "aLSrH7DPkcGz2Sxz9otKbAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-30 20:58:26
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 30 16:58:18.192179 2025] [security2:error] [pid 25725:tid 25725] [client 2a0f:df00:0:255::203:39214] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cauchosindustrialesespeciales.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cauchosindustrialesespeciales.com"] [uri "/cauchosind.sql"] [unique_id "aLNl6iKUFcTk2sNPPKIJhgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-29 15:47:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 29 11:47:34.588715 2025] [security2:error] [pid 6596:tid 6596] [client 2a0f:df00:0:255::203:53118] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||stinsonbeachsurfandkayak.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stinsonbeachsurfandkayak.com"] [uri "/.sql"] [unique_id "aLHLluv5lOV-b8-DCNpKLAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
1gz
2025-08-28 22:50:17
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST me ...
show more
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST method)
Endpoint: /auth/login
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.0) Gecko/20100101 Firefox/128.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-08-20 23:53:54
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 20 19:53:44.742650 2025] [security2:error] [pid 28576:tid 28576] [client 2a0f:df00:0:255::203:42210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||disenowebprofesional.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disenowebprofesional.com"] [uri "/senowebprofesional.sql"] [unique_id "aKZgCPlJ0uzoKot7IP_NhgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-19 15:32:38
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 19 11:32:31.031879 2025] [security2:error] [pid 2377064:tid 2377064] [client 2a0f:df00:0:255::203:59082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newhopepetgrooming.com"] [uri "/wp-config.php.bak."] [unique_id "aFQtj6ZwajAXw3EIMQV0DQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2025-05-30 11:15:30
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
π©πͺ
LRob
2025-05-30 10:45:33
(1 year ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
π©πͺ
LRob
2025-05-30 10:30:14
(1 year ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
πΊπΈ
TPI-Abuse
2025-05-22 15:48:46
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 22 11:48:38.963107 2025] [security2:error] [pid 3689544:tid 3689544] [client 2a0f:df00:0:255::203:50682] [client 2a0f:df00:0:255::203] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pa-ksa.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pa-ksa.com"] [uri "/docs/Zfjryxj.dat"] [unique_id "aC9HVm-28m7Sl7os5HWEsQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-22 12:15:43
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 22 08:15:35.411274 2025] [security2:error] [pid 534600:tid 534600] [client 2a0f:df00:0:255::203:50402] [client 2a0f:df00:0:255::203] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nwuoregon.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nwuoregon.org"] [uri "/bd.sql"] [unique_id "aC8VZ8d_V7eig2tEBUSz5gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-16 17:12:10
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::203 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 13:12:02.306786 2025] [security2:error] [pid 438041:tid 438041] [client 2a0f:df00:0:255::203:41548] [client 2a0f:df00:0:255::203] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||itibitico.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "itibitico.com"] [uri "/migration.sql"] [unique_id "aCdx4uCGCJDTuPV8lAF-WAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack