๐บ๐ธ
xmission.com
2026-07-14 07:19:57
(1 week ago)
Blocked by UFW (TCP on 1)
Source port: 44178
TTL: 107
Packet length: 52
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 1)
Source port: 44178
TTL: 107
Packet length: 52
TOS: 0x08
This report (for 102.216.39.10) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-06-25 17:30:07
(1 month ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
Exploited Host
Bad Web Bot
๐ฎ๐ฉ
hermawan
2026-06-08 01:29:30
(1 month ago)
[Mon Jun 08 08:29:28.958596 2026] [security2:error] [pid 537119:tid 140380620191424] [client 102.216 ...
show more
[Mon Jun 08 08:29:28.958596 2026] [security2:error] [pid 537119:tid 140380620191424] [client 102.216.39.10:42042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555561495-infografis-waspada-cuaca-ekstrem-di-masa-pancaroba HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555561495-infografis-waspada-cuaca-ekstrem-di-masa-pancaroba"] [unique_id "aiYa-JSMQV4uwoRvBSdXAAABwwA"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[537128] [bNwG8XPtv+Y] [aiYa-JSMQV4uwoRvBSdXAAABwwA]
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-04 15:31:37
(1 month ago)
[Thu Jun 04 22:31:33.909258 2026] [security2:error] [pid 310102:tid 139764423382720] [client 102.216 ...
show more
[Thu Jun 04 22:31:33.909258 2026] [security2:error] [pid 310102:tid 139764423382720] [client 102.216.39.10:28058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /gtagku_staklim-jatim_bmkg_go_id-v1.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/gtagku_staklim-jatim_bmkg_go_id-v1.js"] [unique_id "aiGaVZVpzQ1Y1BYD8FffYAAAUBM"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[310128] [TbgsPe/gA4s] [aiGaVZVpzQ1Y1BYD8FffYAAAUBM] keep_alive=[1] [2026-06-04 22:31:33.909262] [R:aiGaVZVpzQ1Y1BYD8FffYAAAUBM] UA:'Mozilla/5.0 (Linux; Android 13; SM-A325M Build/TP1A.220624.014; ) AppleWebKit/537.36 (KHTML, like Ge
...
show less
Email Spam
Hacking
๐ณ๐ฑ
exxos
2025-08-31 23:03:01
(10 months ago)
Attacks with Bad user agents
Hacking
๐บ๐ธ
TPI-Abuse
2025-07-09 15:50:28
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 102.216.39.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 102.216.39.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 09 11:50:20.168280 2025] [security2:error] [pid 4246:tid 4250] [client 102.216.39.10:42581] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.killasgarage.bike|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.killasgarage.bike"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aG6PvOlJj4E92O99a6C66QAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-22 17:50:35
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 102.216.39.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 102.216.39.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 13:50:30.685824 2025] [security2:error] [pid 3783938:tid 3783938] [client 102.216.39.10:1287] [client 102.216.39.10] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cosplayculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cosplayculture.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aAfW5i_Fw985dqZzDULs9gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ManagedStack
2025-04-15 01:22:54
(1 year ago)
Wordpress Attack
Web App Attack
Anonymous
2025-01-17 21:41:24
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐ฆ๐บ
MAGIC
2025-01-03 11:09:11
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2024-12-31 22:37:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2024-12-30 15:15:03
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-12-29 20:22:52
(1 year ago)
102.216.39.10 - - [29/Dec/2024:22:22:50 +0200] "GET /wp-login.php HTTP/1.1" 404 2618 "-" "Mozilla/5. ...
show more
102.216.39.10 - - [29/Dec/2024:22:22:50 +0200] "GET /wp-login.php HTTP/1.1" 404 2618 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
102.216.39.10 - - [29/Dec/2024:22:22:51 +0200] "GET /xmlrpc.php HTTP/1.1" 404 366 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
...
show less
Web App Attack
๐ฆ๐บ
MAGIC
2024-12-18 23:08:10
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2024-11-19 10:54:01
(1 year ago)
Malicious activity detected
Hacking
Web App Attack