๐บ๐ธ
xmission.com
2026-06-23 03:24:43
(2 months ago)
Blocked by UFW (TCP on 8888)
Source port: 61011
TTL: 241
Packet length: 44
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 8888)
Source port: 61011
TTL: 241
Packet length: 44
TOS: 0x08
This report (for 142.93.65.244) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ธ๐ช
SkyDancer
2026-06-23 02:47:51
(2 months ago)
Multiple intrusion attempts via RDP. Attack automatically blocked by SkyDancer Ai(RDP-X).
Hacking
Brute-Force
๐ฉ๐ช
zupan
2026-06-19 05:38:40
(3 months ago)
Blocked by UFW on vps [8088/tcp] | SPT: 61000 | TTL: 237 | LEN: 44 | TOS: 0x00 โข Reported by: github ...
show more
Blocked by UFW on vps [8088/tcp] | SPT: 61000 | TTL: 237 | LEN: 44 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-06-01 22:00:24
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-31.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-06-01 07:32:58
(3 months ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=15
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-01 03:09:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 142.93.65.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 142.93.65.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 23:08:57.769562 2026] [security2:error] [pid 13677:tid 13677] [client 142.93.65.244:58443] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acatucson.com"] [uri "/.env"] [unique_id "ahz3ya1Iz_1mz4gobrORXQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
serverutama
2026-05-31 23:49:01
(3 months ago)
Nginx scanner: 142.93.65.244 - - [01/Jun/2026:06:46:56 +0700] "GET /.env HTTP/1.1" 444 0 "-" "Mozill ...
show more
Nginx scanner: 142.93.65.244 - - [01/Jun/2026:06:46:56 +0700] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" 142.93.65.244 - - [01/Jun/2026:06:46:57 +0700] "GET /.env HTTP/1.1" 444 0 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "-"
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-31 23:06:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 142.93.65.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 142.93.65.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 19:06:34.238124 2026] [security2:error] [pid 27983:tid 28001] [client 142.93.65.244:65374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adultbaja.com"] [uri "/.env"] [unique_id "ahy--gUkg5M6BKEZ1IjEmAAAAY8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-31 22:30:02
(3 months ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 21:34:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 142.93.65.244 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 142.93.65.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 17:34:52.676708 2026] [security2:error] [pid 21244:tid 21263] [client 142.93.65.244:62068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "8mm-stockfootage.com"] [uri "/.env"] [unique_id "ahypfFVRUkxpZ0tiXpK6sQAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-31 21:21:49
(3 months ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-31 21:18:25
(3 months ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/sendgrid/.env
Web App Attack
๐จ๐ญ
4server
2026-05-31 19:49:25
(3 months ago)
[SunMay3121:49:22.5126282026][security2:error][pid988075:tid988398][client142.93.65.244:0]ModSecurit ...
show more
[SunMay3121:49:22.5126282026][security2:error][pid988075:tid988398][client142.93.65.244:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"4server.biz\"][uri\"/.env\"][unique_id\"ahyQwmHKXsVYvrktocJdNQAAAQU\"]
show less
Hacking
Web App Attack
๐ซ๐ท
Altai
2026-05-29 21:08:25
(3 months ago)
Blocked by UFW on Jellyfin [2087/tcp]
Source port: 58640
TTL: 112
Packet length: 52
TOS: 0x08
This ...
show more
Blocked by UFW on Jellyfin [2087/tcp]
Source port: 58640
TTL: 112
Packet length: 52
TOS: 0x08
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
MPL
2026-05-29 07:28:45
(3 months ago)
tcp/2087 (6 or more attempts)
Port Scan