๐บ๐ธ
xmission.com
2026-07-27 15:27:38
(1 day ago)
Blocked by UFW (TCP on 6881)
Source port: 4543
TTL: 115
Packet length: 52
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 6881)
Source port: 4543
TTL: 115
Packet length: 52
TOS: 0x08
This report (for 155.2.216.30) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-07-16 16:30:03
(1 week ago)
CrowdSec decision: LePresidente/http-generic-401-bf (origin: crowdsec)
Port Scan
๐บ๐ธ
xmission.com
2026-07-08 13:59:39
(2 weeks ago)
Blocked by UFW (TCP on 6881)
Source port: 62529
TTL: 54
Packet length: 64
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 6881)
Source port: 62529
TTL: 54
Packet length: 64
TOS: 0x08
This report (for 155.2.216.30) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ซ๐ฎ
notelseit
2026-07-08 01:08:50
(3 weeks ago)
2026-07-08T03:08:42.238246+02:00 mail postfix/submission/smtpd[1298736]: warning: unknown[155.2.216. ...
show more
2026-07-08T03:08:42.238246+02:00 mail postfix/submission/smtpd[1298736]: warning: unknown[155.2.216.30]: SASL LOGIN authentication failed: (reason unavailable), [email protected]
2026-07-08T03:08:42.523419+02:00 mail postfix/submission/smtpd[1298736]: disconnect from unknown[155.2.216.30] ehlo=2 starttls=1 auth=0/1 commands=3/4
2026-07-08T03:08:50.319270+02:00 mail postfix/submission/smtpd[1298736]: warning: unknown[155.2.216.30]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=info
...
show less
Brute-Force
Email Spam
๐ฏ๐ต
demonsword
2026-07-07 08:23:38
(3 weeks ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: cloudflare.com:443
show less
Open Proxy
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-03 22:08:04
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 18:07:56.810758 2026] [security2:error] [pid 26033:tid 26033] [client 155.2.216.30:45821] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drbbenefits.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drbbenefits.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgyvL4w2az4ZqqTPcGnBAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 21:45:26
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 17:45:20.512124 2026] [security2:error] [pid 4900:tid 4900] [client 155.2.216.30:40275] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||zztp.ws|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zztp.ws"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgtcGjAkmgKYkUNZWPXcgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 21:24:34
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 17:24:27.057496 2026] [security2:error] [pid 1784:tid 1784] [client 155.2.216.30:25205] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||saynotoofland.org|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "saynotoofland.org"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgoi0Ybj8BCRH798VeSFwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 21:04:34
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 17:04:28.242938 2026] [security2:error] [pid 2971:tid 2971] [client 155.2.216.30:53139] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cyber507.net|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cyber507.net"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgj3AlWIxhpHLdULa0NmgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 20:45:48
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 16:45:42.506341 2026] [security2:error] [pid 15071:tid 15071] [client 155.2.216.30:42311] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||callahan-co.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "callahan-co.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgfdh_aTypX02CJ2rOJhwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 20:22:12
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 16:22:07.240197 2026] [security2:error] [pid 3489:tid 3489] [client 155.2.216.30:26311] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scriptediting.uk|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scriptediting.uk"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgZ72L-qz4Fm20OiaIYlQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 20:03:18
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 16:03:15.813715 2026] [security2:error] [pid 9436:tid 9436] [client 155.2.216.30:62383] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mcgmcg.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mcgmcg.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgVg7FylcY_HH0tP1asRwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 19:43:46
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 15:43:37.888205 2026] [security2:error] [pid 2016:tid 2016] [client 155.2.216.30:39513] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aliamus.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aliamus.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgQ6f0d5f8R-viklvaPwwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 19:23:31
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 15:23:26.914930 2026] [security2:error] [pid 23164:tid 23164] [client 155.2.216.30:62963] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dplmat.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgMLlcNLtxSYDF5zK5HlwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 19:02:49
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 155.2.216.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 15:02:43.823702 2026] [security2:error] [pid 26187:tid 26187] [client 155.2.216.30:47433] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dynarol.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dynarol.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "akgHU32IC3q9S8GbUrz6CgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack