๐จ๐ณ
pengpeng
2026-06-24 15:03:02
(2 days ago)
monitor: on VM-0-7-ubuntu | port: 6881 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
Port Scan
Anonymous
2026-06-03 05:00:56
(3 weeks ago)
BruteForce IMAP/POP3/SMTP
Brute-Force
๐จ๐ฟ
lp
2026-06-02 21:20:59
(3 weeks ago)
Email account brute force: 4 attempts were recorded from 149.102.246.19
2026-06-02T22:47:29+02:00 wa ...
show more
Email account brute force: 4 attempts were recorded from 149.102.246.19
2026-06-02T22:47:29+02:00 warning: unknown[149.102.246.19]: SASL PLAIN authentication failed: authentication failure, [email protected]
2026-06-02T22:47:29+02:00 warning: unknown[149.102.246.19]: SASL LOGIN authentication failed: authentication failure, [email protected]
2026-06-02T22:47:53+02:00 warning: unknown[149.102.246.19]: SASL PLAIN authentication failed: authentication failure, [email protected]
2026-06-02T22:47:53+02:00 warning: unknown[149.102.246.19]: SASL LOGIN authentication failed: authentication failure, [email protected]
show less
Brute-Force
๐ซ๐ฎ
notelseit
2026-06-02 20:33:19
(3 weeks ago)
2026-06-02T22:33:12.437730+02:00 mail postfix/submission/smtpd[3893246]: warning: unknown[149.102.24 ...
show more
2026-06-02T22:33:12.437730+02:00 mail postfix/submission/smtpd[3893246]: warning: unknown[149.102.246.19]: SASL PLAIN authentication failed: (reason unavailable), [email protected]
2026-06-02T22:33:18.425312+02:00 mail postfix/submission/smtpd[3893246]: warning: unknown[149.102.246.19]: SASL LOGIN authentication failed: (reason unavailable), [email protected]
2026-06-02T22:33:18.654032+02:00 mail postfix/submission/smtpd[3893246]: disconnect from unknown[149.102.246.19] ehlo=2 starttls=1 auth=0/2 quit=1 commands=4/6
...
show less
Brute-Force
Email Spam
๐ฉ๐ช
FeG Deutschland
2026-04-12 05:34:43
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 28
Exploited Host
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-04-10 21:51:10
(2 months ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
Anonymous
2026-03-29 11:12:17
(2 months ago)
Suspicious activity detected in web server access logs
Web App Attack
๐ช๐ธ
librebit
2026-03-29 02:35:54
(2 months ago)
Brute force
Brute-Force
๐ท๐บ
Agrohim
2026-03-27 14:34:19
(2 months ago)
Gate Inet blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
๐บ๐ธ
xmission.com
2026-03-26 23:26:02
(3 months ago)
Blocked by UFW (TCP on 61976)
Source port: 42806
TTL: 39
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 61976)
Source port: 42806
TTL: 39
Packet length: 60
TOS: 0x08
This report (for 149.102.246.19) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
HandyTreff.de
2026-03-20 17:44:58
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -70.985 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -70.985 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Linux; Android 10; Redmi Note 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
jcbriar
2026-03-16 08:28:22
(3 months ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐ฉ๐ช
onlyops.app
2026-03-16 08:00:23
(3 months ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
๐ซ๐ท
masterguru
2026-03-16 07:38:42
(3 months ago)
Host header is a numeric IP address. Pattern match "^ (920350-143)
Hacking
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-03-16 07:36:56
(3 months ago)
[Mon Mar 16 08:36:54.072040 2026] [security2:error] [pid 2493822:tid 2493839] [client 149.102.246.19 ...
show more
[Mon Mar 16 08:36:54.072040 2026] [security2:error] [pid 2493822:tid 2493839] [client 149.102.246.19:55662] [client 149.102.246.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "95.216.72.247"] [uri "/.env"] [unique_id "abezFsSvcjxeB8YwXHGGIgAAAEo"]
[Mon Mar 16 08:36:55.430079 2026] [security2:error] [pid 2492391:tid 2492400] [client 149.102.246.19:58671] [client 149.102.246.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [t
...
show less
Web App Attack
Bad Web Bot