๐ซ๐ท
Soncraft
2026-06-23 20:57:12
(7 hours ago)
Blocked by UFW on Jellyfin [23/tcp]
Source port: 38975
TTL: 54
Packet length: 60
TOS: 0x08
This rep ...
show more
Blocked by UFW on Jellyfin [23/tcp]
Source port: 38975
TTL: 54
Packet length: 60
TOS: 0x08
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
mnsf
2026-06-13 01:05:18
(1 week ago)
Abuse Detected (2)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-13 00:36:46
(1 week ago)
150 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-13 00:13:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 149.34.244.153 (unn-149-34-244-153.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.34.244.153 (unn-149-34-244-153.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 20:13:47.266813 2026] [security2:error] [pid 14662:tid 14662] [client 149.34.244.153:16628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bamedica.com"] [uri "/.git/config"] [unique_id "aiygu9_Apw6nv7DT1bH39AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-06-12 23:50:59
(1 week ago)
Sensitive File Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 23:39:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 149.34.244.153 (unn-149-34-244-153.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.34.244.153 (unn-149-34-244-153.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 19:39:31.465766 2026] [security2:error] [pid 13742:tid 13742] [client 149.34.244.153:56266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "balmedia.com"] [uri "/.git/config"] [unique_id "aiyYs2HG4ldDxu_rv_Dr3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-06-12 23:39:27
(1 week ago)
Suricata: Alert - ET INFO Python aiohttp User-Agent Observed Inbound
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-12 23:26:27
(1 week ago)
Unauthorized access to webpage admin
Web App Attack
๐ซ๐ฎ
as211431.net
2026-02-27 09:34:18
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/3 ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/3 (GET method)
Endpoint: /cdn-cgi/zaraz/s.js
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-02-16 10:09:47
(4 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
Rayulcifer
2026-02-15 11:21:29
(4 months ago)
149.34.244.153 - - [15/Feb/2026:06:20:26 -0500] "GET http://52.24.104.170:8086/RestSimulator?Operati ...
show more
149.34.244.153 - - [15/Feb/2026:06:20:26 -0500] "GET http://52.24.104.170:8086/RestSimulator?Operation=postDonation&available_patriotism=0&company_id=4346387&company_name=%E2%98%A0%EF%B8%8FDevil%27s+Grim%E2%98%A0%EF%B8%8FUS%28GA%29&country=Nigeria&donation_sum=100000000000&donation_type=0&sender_company_id=4346387&user_id=C4028912C33146F38CAB4ED760F28D2D&version_code=22&war_id=57682 HTTP/1.1" 200 911 "-" "android-asynchttp://loopj.com/android-async-http"
149.34.244.153 - - [15/Feb/2026:06:21:28 -0500] "GET http://52.24.104.170:8086/RestSimulator?Operation=postDonation&available_patriotism=0&company_id=4346387&company_name=%E2%98%A0%EF%B8%8FDevil%27s+Grim%E2%98%A0%EF%B8%8FUS%28GA%29&country=Nigeria&donation_sum=100000000000&donation_type=0&sender_company_id=4346387&user_id=C4028912C33146F38CAB4ED760F28D2D&version_code=22&war_id=57682 HTTP/1.1" 200 911 "-" "android-asynchttp://loopj.com/android-async-http"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-10 21:26:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.34.244.153 (unn-149-34-244-153.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.34.244.153 (unn-149-34-244-153.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 16:26:26.765591 2026] [security2:error] [pid 21520:tid 21520] [client 149.34.244.153:18418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinnen.org"] [uri "/.git/config"] [unique_id "aYuiguXF3v70V-cNPePg2QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-09 15:34:43
(5 months ago)
Aggressive web graphql scan
Web App Attack
๐ง๐ท
SOC Blue Team
2025-12-19 15:56:14
(6 months ago)
Tatic: TA0006 | Technique: T1110 | Source: TAP | Country Destination: BR
Brute-Force
๐ฎ๐ฉ
sockominfo
2025-12-10 07:39:38
(6 months ago)
[WAZUH] SUPPRESSED: IP 149.34.244.153 blocked - 8 times fired in 6 hour
Hacking
Web App Attack