๐บ๐ธ
xmission.com
2026-06-07 18:52:06
(9 hours ago)
Blocked by UFW (TCP on 52000)
Source port: 9100
TTL: 48
Packet length: 76
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 52000)
Source port: 9100
TTL: 48
Packet length: 76
TOS: 0x08
This report (for 149.102.153.38) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-06 15:31:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 11:31:51.695467 2026] [security2:error] [pid 5071:tid 5071] [client 149.102.153.38:11328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.km-herbs.com"] [uri "/.git/config"] [unique_id "aiQ9Z7PSQXlPl3ymretPKwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-06-05 13:41:38
(2 days ago)
Blocked by UFW (TCP on 47820)
Source port: 9100
TTL: 49
Packet length: 76
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 47820)
Source port: 9100
TTL: 49
Packet length: 76
TOS: 0x08
This report (for 149.102.153.38) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-05 12:24:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 08:24:04.426592 2026] [security2:error] [pid 6609:tid 6609] [client 149.102.153.38:35534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.waleed-alshalan.com"] [uri "/.git/config"] [unique_id "aiK_5PKZ0mVXKZ687EHbiQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 11:10:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 07:10:41.369361 2026] [security2:error] [pid 29773:tid 29773] [client 149.102.153.38:36116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.barpubsigns.com"] [uri "/.git/config"] [unique_id "aiKusa6Ta1zNNXdRqSSNmAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-05 06:05:34
(2 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 00:01:58
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 20:01:54.897952 2026] [security2:error] [pid 22021:tid 22021] [client 149.102.153.38:35058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.austintrauma.com"] [uri "/.git/config"] [unique_id "aiIR8m2bc4NNbMtWzqvS_wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-06-03 10:45:42
(4 days ago)
Blocked by UFW (TCP on 40396)
Source port: 9100
TTL: 49
Packet length: 76
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 40396)
Source port: 9100
TTL: 49
Packet length: 76
TOS: 0x08
This report (for 149.102.153.38) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฆ๐บ
paulshipley.com.au
2026-06-03 02:50:00
(5 days ago)
[Wed Jun 03 12:49:59.581372 2026] [security2:error] [pid 325081] [client 149.102.153.38:61208] [clie ...
show more
[Wed Jun 03 12:49:59.581372 2026] [security2:error] [pid 325081] [client 149.102.153.38:61208] [client 149.102.153.38] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "shotbysuzanne.com.au"] [uri "/"] [unique_id "ah-WV9SyWAU6PW4D5PmCUgAAAAg"]
...
show less
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-02 00:18:42
(6 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 06:50:41
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 02:50:35.321134 2026] [security2:error] [pid 27392:tid 27392] [client 149.102.153.38:11410] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||munnich.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "munnich.net"] [uri "/dump.sql"] [unique_id "ah0ru9BlVxJi8yEemJ-ghgAAAAI"], referer: munnich.net/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-06-01 04:39:28
(6 days ago)
Blocked by UFW (TCP on 35588)
Source port: 9000
TTL: 48
Packet length: 76
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 35588)
Source port: 9000
TTL: 48
Packet length: 76
TOS: 0x08
This report (for 149.102.153.38) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ซ๐ท
Kenshin869
2026-05-30 23:49:18
(1 week ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-30 23:15:55
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 19:15:50.875297 2026] [security2:error] [pid 5680:tid 5680] [client 149.102.153.38:43194] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cswiki.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cswiki.us"] [uri "/dump.sql"] [unique_id "ahtvpiedO3zM3792RlrmjAAAAAI"], referer: cswiki.us/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 12:43:37
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 149.102.153.38 (uk1tor.quetzalcoatl-relays.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 08:43:31.778359 2026] [security2:error] [pid 21844:tid 21844] [client 149.102.153.38:18006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||firewoodart.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "firewoodart.com"] [uri "/dump.sql"] [unique_id "ahrbcySbT9K3SK-xPtn9lAAAAAE"], referer: firewoodart.com/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack