๐ฉ๐ช
Sculk Ltd.
2026-06-01 11:34:04
(3 weeks ago)
Unsolicited Minecraft server-list ping (handshake/status) to TCP/25565 across 17 address(es); protoc ...
show more
Unsolicited Minecraft server-list ping (handshake/status) to TCP/25565 across 17 address(es); protocol 1.20.3. Automated port scan detected by a Velocity proxy.
show less
Port Scan
๐จ๐ญ
barateza
2026-03-25 03:00:03
(3 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 13:58:30
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 08:58:24.342999 2026] [security2:error] [pid 30383:tid 30383] [client 158.173.24.35:48979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cliniquecavalancia.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aY8uAK8uoa62EgV6LrTZ-wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 11:55:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 06:55:11.107961 2026] [security2:error] [pid 7476:tid 7476] [client 158.173.24.35:58684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christineaholtz.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aY8RH3bLRKk8qm2cXEk8ygAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-13 11:06:04
(4 months ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 09:38:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 04:38:45.906066 2026] [security2:error] [pid 30720:tid 30755] [client 158.173.24.35:28362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clearwaterpumpservices.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aY7xJXLiWKzp-rMQ30LewwAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 06:54:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 01:54:42.331782 2026] [security2:error] [pid 23089:tid 23089] [client 158.173.24.35:36508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clayrivers.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aY7Ksq1ZBUkNl80vCh1bBwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
RoboSOC
2026-02-13 06:42:50
(4 months ago)
HTTP Directory Traversal Vulnerability , PTR: PTR record not found
Hacking
๐ฌ๐ง
consul.to
2026-02-13 05:47:00
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 05:26:56
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.24.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 00:26:50.181856 2026] [security2:error] [pid 7061:tid 7061] [client 158.173.24.35:50191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chinookdrivingacademy.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aY62Gg2ExksO044_U63IdQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-01-10 02:40:42
(5 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
xmission.com
2025-10-06 04:28:24
(8 months ago)
Blocked by UFW (TCP on 6881)
Source port: 19857
TTL: 115
Packet length: 52
TOS: 0x00
This report (f ...
show more
Blocked by UFW (TCP on 6881)
Source port: 19857
TTL: 115
Packet length: 52
TOS: 0x00
This report (for 158.173.24.35) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan