Anonymous
2026-10-01 17:12:30
(1 week ago)
CrowdSec: crowdsecurity/iptables-scan-multi_ports
Port Scan
๐จ๐ฟ
lp
2026-10-01 15:55:08
(1 week ago)
anomaly: tcp_port_scan, 501 > threshold 500, repeats 20077 times
Port Scan
๐ต๐ฑ
sefinek.net
2026-10-01 13:15:32
(1 week ago)
Honeypot hit: HTTP/1.1 request on 7777
GET /
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:153.0) ...
show more
Honeypot hit: HTTP/1.1 request on 7777
GET /
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:153.0) Gecko/20100101 Firefox/153.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate; 7777 [2] TCP
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Hacking
Bad Web Bot
๐บ๐ธ
MPL
2026-10-01 12:12:27
(1 week ago)
tcp/1177 (2 or more attempts)
Port Scan
๐บ๐ธ
xmission.com
2026-10-01 11:54:45
(1 week ago)
Blocked by UFW (TCP on 8048)
Source port: 61002
TTL: 237
Packet length: 44
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 8048)
Source port: 61002
TTL: 237
Packet length: 44
TOS: 0x08
This report (for 139.59.139.11) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-10-01 11:25:36
(1 week ago)
denied traffic to a honeypot network. destination port 3000.
Port Scan
Hacking
๐ง๐ช
boxed-it
2026-09-04 15:30:59
(1 month ago)
GET /.git/config (Tarpitted for 1d15h8m29s, wasted 8.06MB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 23:32:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 139.59.139.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.139.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:32:27.473534 2026] [security2:error] [pid 8442:tid 8442] [client 139.59.139.11:37328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bcmech.com"] [uri "/.git/config"] [unique_id "apoDi_U8fLiTrMi4F2rEpwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 21:10:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 139.59.139.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.139.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:10:24.001720 2026] [security2:error] [pid 26965:tid 26965] [client 139.59.139.11:39972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bcbikini.com.puckerbikini.com"] [uri "/.git/config"] [unique_id "apniQB_xeu407jK15rYcBAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 19:01:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 139.59.139.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.139.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:01:38.036354 2026] [security2:error] [pid 13610:tid 13709] [client 139.59.139.11:43830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbpuertadelsol.com"] [uri "/.git/config"] [unique_id "apnEEjQw0ZchTMYjczkivQAAAkw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-03 18:55:48
(1 month ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 18:30:03
(1 month ago)
CrowdSec decision: crowdsecurity/CVE-2017-9841 (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-03 18:17:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 139.59.139.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.139.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:17:43.232566 2026] [security2:error] [pid 13928:tid 13928] [client 139.59.139.11:51442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbc.my1611.com"] [uri "/.git/config"] [unique_id "apm5x5UcQq-Xa7EHtnVpJwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 17:57:39
(1 month ago)
XSS Attempt
Hacking
๐ฎ๐น
CoreTech srl
2026-09-03 17:48:57
(1 month ago)
cloudlinux2 fail2ban: 2026-09-03 19:44:29,548 fail2ban.filter [1472]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-03 19:44:29,548 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 107.167.181.44 - 2026-09-03 19:44:29cloudlinux2 fail2ban: 2026-09-03 19:44:43,083 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 66.32.64.20 - 2026-09-03 19:44:43cloudlinux2 fail2ban: 2026-09-03 19:44:45,861 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 66.32.64.20 - 2026-09-03 19:44:43cloudlinux2 fail2ban: 2026-09-03 19:44:52,228 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 35.229.65.180 - 2026-09-03 19:44:52cloudlinux2 fail2ban: 2026-09-03 19:45:01,628 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 207.154.247.228 - 2026-09-03 19:45:01cloudlinux2 fail2ban: 2026-09-03 19:45:03,063 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 45.132.115.249 - 2026-09-03 19:45:01cloudlinux2 fail2ban: 2026-09-03 19:45:01,447 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 207.154.247.228 - 2026-09-03 19:45
show less
Web App Attack