๐บ๐ธ
xmission.com
2026-09-26 00:04:16
(1 hour ago)
Blocked by UFW (TCP on 58140)
Source port: 58763
TTL: 118
Packet length: 52
TOS: 0x08
This report ( ...
show more
Blocked by UFW (TCP on 58140)
Source port: 58763
TTL: 118
Packet length: 52
TOS: 0x08
This report (for 149.22.87.40) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-09-14 20:13:23
(1 week ago)
Authentication failure
Brute-Force
๐บ๐ธ
xmission.com
2026-08-26 05:27:18
(4 weeks ago)
Blocked by UFW (TCP on 1)
Source port: 49674
TTL: 118
Packet length: 52
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 1)
Source port: 49674
TTL: 118
Packet length: 52
TOS: 0x08
This report (for 149.22.87.40) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ซ๐ฎ
notelseit
2026-08-17 15:30:09
(1 month ago)
2026-08-17T17:29:59.165283+02:00 mail postfix/submission/smtpd[373511]: warning: unknown[149.22.87.4 ...
show more
2026-08-17T17:29:59.165283+02:00 mail postfix/submission/smtpd[373511]: warning: unknown[149.22.87.40]: SASL LOGIN authentication failed: (reason unavailable), [email protected]
2026-08-17T17:29:59.451517+02:00 mail postfix/submission/smtpd[373511]: disconnect from unknown[149.22.87.40] ehlo=2 starttls=1 auth=0/1 commands=3/4
2026-08-17T17:30:09.255540+02:00 mail postfix/submission/smtpd[373511]: warning: unknown[149.22.87.40]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=info
...
show less
Brute-Force
Email Spam
๐ซ๐ท
matthieul.dev
2026-07-05 23:45:18
(2 months ago)
Blocked by os-abuseipdb; 5 hits, proto=tcp, ports=59261
Port Scan
Brute-Force
๐บ๐ธ
Penny Packer
2026-06-28 14:44:10
(2 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 19:35:46
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 15:35:39.702745 2026] [security2:error] [pid 5841:tid 5841] [client 149.22.87.40:54385] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.oualierealty.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.oualierealty.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akAmC8iFLH8xQ5nTxXLfZAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 19:13:41
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 15:13:35.427161 2026] [security2:error] [pid 16245:tid 16245] [client 149.22.87.40:34345] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nextlevelcharge.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nextlevelcharge.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akAg32BqbgB5rlTSR6mgrgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 18:29:55
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 14:29:50.252358 2026] [security2:error] [pid 30250:tid 30250] [client 149.22.87.40:33211] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.amazingwelding.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.amazingwelding.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akAWnqnJ6qCyhiJYkq4PXgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 13:14:32
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 09:14:27.248632 2026] [security2:error] [pid 25311:tid 25311] [client 149.22.87.40:28563] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||namefinder.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "namefinder.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj_Ms7Wvzd71uPaFGVWjXAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 02:54:05
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 22:54:00.674424 2026] [security2:error] [pid 16022:tid 16022] [client 149.22.87.40:54641] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||caonabo.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caonabo.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj87SDx0bmstU6-WObjlaAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 02:30:42
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 22:30:39.556163 2026] [security2:error] [pid 18310:tid 18354] [client 149.22.87.40:20033] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.biblewriter.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.biblewriter.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj81z54ldKi8DBfAqxyMQQAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 02:02:13
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 22:02:09.094672 2026] [security2:error] [pid 26567:tid 26567] [client 149.22.87.40:25617] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lisalehmann.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lisalehmann.com"] [uri "/photography.html/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj8vIf7js-RPu6N7rvSU3wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 01:20:53
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 21:20:47.019522 2026] [security2:error] [pid 31989:tid 31996] [client 149.22.87.40:28829] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.davidholls.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.davidholls.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj8lbwVg3LUjtmM3N5Y5GwAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 00:46:37
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.22.87.40 (unn-149-22-87-40.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 20:46:30.701489 2026] [security2:error] [pid 16924:tid 16924] [client 149.22.87.40:25499] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||perthdps.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "perthdps.com"] [uri "/convicts/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aj8dZpgRqh_nGQrPGDsKhQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack