Anonymous
2026-06-18 01:38:31
(1 day ago)
Portscan: TCP/2082, TCP/2087, TCP/2086, TCP/2083, TCP/2095, TCP/2096, TCP/443, TCP/2078, TCP/2077
Port Scan
๐จ๐ฟ
Countryman
2026-06-17 16:15:53
(1 day ago)
repeated unauthorized connection attempts, host sweep, port scan
Port Scan
๐ต๐ฑ
Tankudoraiba
2026-06-17 13:59:35
(1 day ago)
Unauthorized connection attempts on ports 443|80
Port Scan
Bad Web Bot
๐ฉ๐ช
Hugopvigo
2026-06-17 11:09:28
(1 day ago)
travel.suop.es:80 137.184.130.80 - - [17/Jun/2026:13:09:26 +0200] "GET /.env.production HTTP/1.1" 30 ...
show more
travel.suop.es:80 137.184.130.80 - - [17/Jun/2026:13:09:26 +0200] "GET /.env.production HTTP/1.1" 301 563 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
Prodscape
2026-06-17 11:07:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 137.184.130.80 (US/United States/-): 5 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.130.80 (US/United States/-): 5 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Port Scan
๐ญ๐ฐ
sandra361
2026-06-17 10:19:22
(1 day ago)
Port scan detected: 9 attempts across 9 ports (2077,2082,2083,2086,2087,2095,2096,443,80). | Evidenc ...
show more
Port scan detected: 9 attempts across 9 ports (2077,2082,2083,2086,2087,2095,2096,443,80). | Evidence: GHOST_SCAN: IN=eth0 SRC=137.184.130.80 LEN=60 TOS=0x14 PREC=0x00 TTL=48 ID=47106 DF PROTO=TCP SPT=59424 DPT=2095 WINDOW=64240 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
xmission.com
2026-06-17 09:39:07
(2 days ago)
Blocked by UFW (TCP on 2078)
Source port: 59130
TTL: 50
Packet length: 60
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 2078)
Source port: 59130
TTL: 50
Packet length: 60
TOS: 0x08
This report (for 137.184.130.80) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
DrLex0
2026-06-17 07:37:48
(2 days ago)
Poking for git configs and env files
137.184.130.80 80 - [17/Jun/2026:07:37:41 +0000] "GET /.git/co ...
show more
Poking for git configs and env files
137.184.130.80 80 - [17/Jun/2026:07:37:41 +0000] "GET /.git/config HTTP/1.1" 404 2402 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15"
137.184.130.80 80 - [17/Jun/2026:07:37:42 +0000] "GET /.git/logs/HEAD HTTP/1.1" 404 2402 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Mobile Safari/537.36"
137.184.130.80 80 - [17/Jun/2026:07:37:48 +0000] "GET /.env.local HTTP/1.1" 404 2402 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
kk_it_man
2026-06-17 07:13:02
(2 days ago)
GPL WEB_SERVER .htpasswd access
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-17 06:58:18
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 137.184.130.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 137.184.130.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 02:58:14.464989 2026] [security2:error] [pid 2971:tid 2971] [client 137.184.130.80:33058] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.240"] [uri "/.git/refs/heads/main"] [unique_id "ajJFhsg5jR4fAeeAkdaCsgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-06-17 05:49:55
(2 days ago)
F2B - Malicious activity detected. Excessive port scans. -c23856ef-
Port Scan
๐บ๐ธ
MPL
2026-06-17 03:56:14
(2 days ago)
tcp port scan (10 or more attempts)
Port Scan
๐บ๐ธ
cwytech
2026-06-17 03:27:57
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/pf-geofence-high.
Hacking
๐ง๐ท
SOC PR
2026-06-17 02:36:39
(2 days ago)
IPS: Web Server Enforcement Violation.
Hacking
๐บ๐ธ
Axel
2026-06-17 01:41:47
(2 days ago)
Blocked by UFW on MVI [2096/tcp] | SPT: 57978 | TTL: 49 | LEN: 60 | TOS: 0x00 โข Reported by: github. ...
show more
Blocked by UFW on MVI [2096/tcp] | SPT: 57978 | TTL: 49 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan