๐ฉ๐ช
int8
2026-05-25 19:07:19
(3 weeks ago)
2026-05-25T19:07:19.008994328Z Minecraft server scanner: status request
Port Scan
๐ณ๐ฑ
FREAKISH
2026-05-25 19:06:49
(3 weeks ago)
2026-05-25 21:06:49: Minecraft server scan detected from 138.199.10.7 on port 25565 of 127.0.0.1
Port Scan
๐บ๐ธ
cpxducky
2026-05-09 06:41:52
(1 month ago)
2026-05-09 06:41:52: Minecraft server scan detected from 138.199.10.7 on port 25565 of mail.cpxducky ...
show more
2026-05-09 06:41:52: Minecraft server scan detected from 138.199.10.7 on port 25565 of mail.cpxducky.com
show less
Port Scan
๐บ๐ธ
xmission.com
2026-03-23 09:24:42
(2 months ago)
Blocked by UFW (TCP on 20747)
Source port: 26232
TTL: 51
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 20747)
Source port: 26232
TTL: 51
Packet length: 60
TOS: 0x08
This report (for 138.199.10.7) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฌ๐ง
consul.to
2026-03-08 14:18:32
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
consul.to
2026-02-11 09:15:57
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
bigscoots.com
2025-11-15 03:40:21
(7 months ago)
(smtpauth) Failed SMTP AUTH login from 138.199.10.7 (US/United States/unn-138-199-10-7.datapacket.co ...
show more
(smtpauth) Failed SMTP AUTH login from 138.199.10.7 (US/United States/unn-138-199-10-7.datapacket.com): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2025-11-14 22:08:35 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:40842: 535 Incorrect authentication data ([email protected] )
2025-11-14 22:08:35 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:40288: 535 Incorrect authentication data ([email protected] )
2025-11-14 22:08:35 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:13526: 535 Incorrect authentication data ([email protected] )
2025-11-14 22:08:35 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:21907: 535 Incorrect authentication data ([email protected] )
2025-11-14 22:40:18 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:28171: 535 Incorrect authentication data ([email protected] )
show less
Brute-Force
SSH
๐บ๐ธ
bigscoots.com
2025-11-15 02:04:35
(7 months ago)
(smtpauth) Failed SMTP AUTH login from 138.199.10.7 (US/United States/unn-138-199-10-7.datapacket.co ...
show more
(smtpauth) Failed SMTP AUTH login from 138.199.10.7 (US/United States/unn-138-199-10-7.datapacket.com): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2025-11-14 20:32:31 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:29686: 535 Incorrect authentication data ([email protected] )
2025-11-14 20:32:31 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:4571: 535 Incorrect authentication data ([email protected] )
2025-11-14 20:32:31 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:2818: 535 Incorrect authentication data ([email protected] )
2025-11-14 20:32:31 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:64906: 535 Incorrect authentication data ([email protected] )
2025-11-14 21:04:34 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:6412: 535 Incorrect authentication data ([email protected] )
show less
Brute-Force
SSH
๐บ๐ธ
bigscoots.com
2025-11-14 06:00:42
(7 months ago)
(smtpauth) Failed SMTP AUTH login from 138.199.10.7 (US/United States/unn-138-199-10-7.datapacket.co ...
show more
(smtpauth) Failed SMTP AUTH login from 138.199.10.7 (US/United States/unn-138-199-10-7.datapacket.com): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2025-11-14 00:28:53 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:31626: 535 Incorrect authentication data ([email protected] )
2025-11-14 00:28:53 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:32735: 535 Incorrect authentication data ([email protected] )
2025-11-14 00:28:53 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:16081: 535 Incorrect authentication data ([email protected] )
2025-11-14 00:28:53 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:40352: 535 Incorrect authentication data ([email protected] )
2025-11-14 01:00:41 dovecot_login authenticator failed for (ADMIN) [138.199.10.7]:51747: 535 Incorrect authentication data ([email protected] )
show less
Brute-Force
SSH
Anonymous
2025-11-14 05:30:40
(7 months ago)
Too many invalid login attempts
Brute-Force
Anonymous
2024-07-23 05:41:13
(1 year ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 15:42:20
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 138.199.10.7 (unn-138-199-10-7.datapacket.com): ...
show more
(mod_security) mod_security (id:210831) triggered by 138.199.10.7 (unn-138-199-10-7.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 11:42:17.387848 2024] [security2:error] [pid 31793] [client 138.199.10.7:34808] [client 138.199.10.7] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.jdpasserlaw.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.jdpasserlaw.com"] [uri "/robots.txt"] [unique_id "ZmsTWUL_BZKIegpMba8RBAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 14:07:32
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 138.199.10.7 (unn-138-199-10-7.datapacket.com): ...
show more
(mod_security) mod_security (id:210831) triggered by 138.199.10.7 (unn-138-199-10-7.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 10:07:27.612138 2024] [security2:error] [pid 6001] [client 138.199.10.7:40616] [client 138.199.10.7] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.gamepart.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.gamepart.com"] [uri "/robots.txt"] [unique_id "Zmr9H5Odx7ZnUkWuTeZWvwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 13:41:52
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 138.199.10.7 (unn-138-199-10-7.datapacket.com): ...
show more
(mod_security) mod_security (id:210831) triggered by 138.199.10.7 (unn-138-199-10-7.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 09:41:47.318176 2024] [security2:error] [pid 3838768] [client 138.199.10.7:60026] [client 138.199.10.7] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.rannals.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.rannals.com"] [uri "/robots.txt"] [unique_id "Zmr3G_oXPdTOvuGItS2yWwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 13:00:18
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 138.199.10.7 (unn-138-199-10-7.datapacket.com): ...
show more
(mod_security) mod_security (id:210831) triggered by 138.199.10.7 (unn-138-199-10-7.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 09:00:14.588953 2024] [security2:error] [pid 29706] [client 138.199.10.7:48992] [client 138.199.10.7] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.satanisdead.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.satanisdead.com"] [uri "/robots.txt"] [unique_id "ZmrtXohGu9QZghMnu34Z8QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack