๐ง๐ท
chronos
2026-05-28 00:04:28
(1 month ago)
2026-05-27 20:24:33 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan
๐ซ๐ท
tavis.page
2026-05-18 05:05:39
(2 months ago)
Blocked by UFW on server [443/tcp]
Source port: 13100
TTL: 55
Packet length: 60
TOS: 0x00
This repo ...
show more
Blocked by UFW on server [443/tcp]
Source port: 13100
TTL: 55
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-15 09:51:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:51:46.333959 2026] [security2:error] [pid 12875:tid 12875] [client 104.23.213.189:12293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drstiso.com"] [uri "/.env.local"] [unique_id "agbsssOLn7d9l3rcjnyFCwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 04:29:29
(2 months ago)
(caddyscan) Scanner path probe from 104.23.213.189 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 104.23.213.189 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.213.189 - - [14/May/2026:03:46:03 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.213.189 - - [14/May/2026:04:07:37 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.213.189 - - [14/May/2026:04:08:30 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.213.189 - - [14/May/2026:04:09:18 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.213.189 - - [14/May/2026:04:29:24 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-09 20:23:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 16:23:49.913850 2026] [security2:error] [pid 18799:tid 18804] [client 104.23.213.189:11140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldcarz.com"] [uri "/.git/config"] [unique_id "af-X1QMidfPJYAlHBEI-BwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 16:42:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 12:42:43.512519 2026] [security2:error] [pid 29989:tid 29989] [client 104.23.213.189:10855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "femalestripperslaquinta.com"] [uri "/.git/config"] [unique_id "af9kA_ft1gifuVaQ9ESsTwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-08 22:05:55
(3 months ago)
Too many Status 40X (14)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-07 21:05:47
(3 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 18:05:21
(3 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐ซ๐ท
tavis.page
2026-04-04 04:25:19
(3 months ago)
Blocked by UFW on server [443/tcp]
Source port: 10605
TTL: 55
Packet length: 60
TOS: 0x00
This repo ...
show more
Blocked by UFW on server [443/tcp]
Source port: 10605
TTL: 55
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
mnsf
2026-04-03 23:06:29
(3 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-02 01:05:15
(3 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 19:54:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 15:54:01.130555 2026] [security2:error] [pid 19385:tid 19385] [client 104.23.213.189:13932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nessmonsters.com"] [uri "/.env.tmp"] [unique_id "acmDWUbyFf5-vq7YHewZ-QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 18:59:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 14:59:12.382223 2026] [security2:error] [pid 27215:tid 27215] [client 104.23.213.189:9725] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aemcmullin.com"] [uri "/public/.env"] [unique_id "acl2gM25tP3g4IGJQ1IO_gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 17:18:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.213.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 13:18:23.949157 2026] [security2:error] [pid 32718:tid 32718] [client 104.23.213.189:10135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hisimengineering.com"] [uri "/.env.example"] [unique_id "acle3wpHNDSoeQsaLt1VTwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack