๐ฉ๐ช
london2038.com
2026-09-26 01:29:56
(2 days ago)
Connection atttempts against closed TCP ports
Sep 26 03:29:55 BLOCK SRC=145.132.101.196 LEN=60 TOS=0 ...
show more
Connection atttempts against closed TCP ports
Sep 26 03:29:55 BLOCK SRC=145.132.101.196 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=13241 DF PROTO=TCP SPT=25664 DPT=2096 WINDOW=64240 RES=0x00 SYN
Sep 26 03:29:55 BLOCK SRC=145.132.101.196 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=22183 DF PROTO=TCP SPT=25668 DPT=8888 WINDOW=64240 RES=0x00 SYN
Sep 26 03:29:55 BLOCK SRC=145.132.101.196 LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=27306 DF PROTO=TCP SPT=25668 DPT=8181 WINDOW=64240 RES=0x00 SYN
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-26 00:39:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 145.132.101.196 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 145.132.101.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 20:39:31.383936 2026] [security2:error] [pid 4048:tid 4048] [client 145.132.101.196:25657] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.226"] [uri "/.env.docker"] [unique_id "arcUQx568WfMqqEDHZ7hHgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 00:35:19
(2 days ago)
denied traffic to a non-approved destination port. destination port 2096.
Port Scan
๐ท๐ธ
Scan
2026-09-26 00:35:14
(2 days ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
๐ฌ๐ง
Axel
2026-09-26 00:21:25
(2 days ago)
Blocked by UFW on BGPGB [443/tcp] | SPT: 25648 | TTL: 108 | LEN: 40 | TOS: 0x00 โข Reported by: githu ...
show more
Blocked by UFW on BGPGB [443/tcp] | SPT: 25648 | TTL: 108 | LEN: 40 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
RAP
2026-09-26 00:04:06
(2 days ago)
2026-09-26 00:04:06 UTC Unauthorized activity to TCP port 8088. Web App
Port Scan
Web App Attack
๐ฎ๐น
VHosting
2026-07-31 22:20:04
(1 month ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐ซ๐ท
ISPLtd
2026-06-11 00:27:17
(3 months ago)
Jun 10 21:27:16 145.132.101.196 TCP SPT=18488 DPT=22 SYN
...
Port Scan
SSH
๐บ๐ธ
TPI-Abuse
2026-06-03 02:06:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 145.132.101.196 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 145.132.101.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 22:06:46.382511 2026] [security2:error] [pid 20185:tid 20185] [client 145.132.101.196:25937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.174"] [uri "/.env"] [unique_id "ah-MNj0Hu-FcUejauKsovgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 01:56:18
(3 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐น๐ท
SeczarSecureOps
2026-06-03 01:49:28
(3 months ago)
Auto-blocked by Seczar SecureOps โ Port Scan Detection (7 events in 10min) at 2026-06-03 01:49
Port Scan
Anonymous
2026-06-03 01:11:45
(3 months ago)
[Wed Jun 03 03:11:25.954382 2026] [authz_core:error] [pid 62599:tid 62670] [client 145.132.101.196:2 ...
show more
[Wed Jun 03 03:11:25.954382 2026] [authz_core:error] [pid 62599:tid 62670] [client 145.132.101.196:27047] AH01630: client denied by server configuration: /var/www/html/.env.local
[Wed Jun 03 03:11:30.243404 2026] [authz_core:error] [pid 62599:tid 62647] [client 145.132.101.196:27076] AH01630: client denied by server configuration: /var/www/html/.env.backup
[Wed Jun 03 03:11:37.463676 2026] [authz_core:error] [pid 62600:tid 62609] [client 145.132.101.196:26125] AH01630: client denied by server configuration: /var/www/html/config
[Wed Jun 03 03:11:41.733283 2026] [authz_core:error] [pid 62599:tid 62658] [client 145.132.101.196:27072] AH01630: client denied by server configuration: /var/www/html/server-status
[Wed Jun 03 03:11:44.657056 2026] [authz_core:error] [pid 62600:tid 62615] [client 145.132.101.196:26160] AH01630: client denied by server configuration: /var/www/html/actuator
...
show less
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-06-03 00:59:06
(3 months ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-09 01:05:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 145.132.101.196 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 145.132.101.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 21:05:23.769095 2026] [security2:error] [pid 2697919:tid 2697919] [client 145.132.101.196:7168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networkzone.org"] [uri "/.env"] [unique_id "adb7U_s3i3Smu4Suh9S37wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-28 22:12:02
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH