๐ซ๐ท
security.rdmc.fr
2026-07-27 14:38:34
(9 hours ago)
Port Scan Attack proto:TCP src:4814 dst:23
Port Scan
Anonymous
2026-07-24 20:56:59
(3 days ago)
denied traffic to a honeypot network. destination port 41311.
Port Scan
Hacking
๐ซ๐ท
Tilellit.PRO
2026-07-20 12:15:18
(1 week ago)
WooCommerce YITH AJAX Filder product_cat filter flood attempt with taxonomies
DDoS Attack
Bad Web Bot
๐ฉ๐ช
Vegascosmetics
2026-06-26 18:09:44
(1 month ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐ณ๐ด
jlouisbiz
2026-04-27 22:57:21
(3 months ago)
2026-04-27T22:54:25.955672+00:00 comm.rcdrun.com auth[543917]: pam_unix(dovecot:auth): authenticatio ...
show more
2026-04-27T22:54:25.955672+00:00 comm.rcdrun.com auth[543917]: pam_unix(dovecot:auth): authentication failure; logname= uid=0 euid=0 tty=dovecot ruser=caesark rhost=149.22.82.29
2026-04-27T22:54:42.421791+00:00 comm.rcdrun.com auth[543917]: pam_unix(dovecot:auth): authentication failure; logname= uid=0 euid=0 tty=dovecot ruser=caesark rhost=149.22.82.29
2026-04-27T22:57:11.904506+00:00 comm.rcdrun.com auth[544180]: pam_unix(dovecot:auth): authentication failure; logname= uid=0 euid=0 tty=dovecot ruser=caesark rhost=149.22.82.29
...
show less
Brute-Force
Anonymous
2026-04-16 02:51:07
(3 months ago)
Malicious activity detected
Hacking
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-04-09 08:34:01
(3 months ago)
Scraping webshop URLs (www.badgehouder.nl), likely botnet drone
Bad Web Bot
Exploited Host
๐จ๐ญ
backslash
2026-03-21 14:27:00
(4 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
Anonymous
2026-02-25 20:32:19
(5 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 06:09:22
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 149.22.82.29 (unn-149-22-82-29.datapacket.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 149.22.82.29 (unn-149-22-82-29.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:09:15.885185 2025] [security2:error] [pid 31786:tid 31786] [client 149.22.82.29:53249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webjemm.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webjemm.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aS0xC0VE5H3q7a8bcv4yswAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 03:43:58
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 149.22.82.29 (unn-149-22-82-29.datapacket.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 149.22.82.29 (unn-149-22-82-29.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 30 22:43:52.199517 2025] [security2:error] [pid 801:tid 801] [client 149.22.82.29:40090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stormwlf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stormwlf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aS0O-AntLVsvKKX-rf5eVQAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-30 20:44:05
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 149.22.82.29 (unn-149-22-82-29.datapacket.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 149.22.82.29 (unn-149-22-82-29.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 30 15:44:02.594285 2025] [security2:error] [pid 21878:tid 21878] [client 149.22.82.29:56569] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||anus.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "anus.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aSyskncAhJ1o02bOpbjASwAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-10-29 12:05:50
(8 months ago)
Attacks with Bad user agents
Hacking
Anonymous
2025-10-15 17:24:00
(9 months ago)
Unauthorized connection attempt
Brute-Force
๐บ๐ธ
xmission.com
2025-09-18 20:58:24
(10 months ago)
Blocked by UFW (TCP on 55756)
Source port: 47838
TTL: 52
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 55756)
Source port: 47838
TTL: 52
Packet length: 60
TOS: 0x08
This report (for 149.22.82.29) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan