π·π΄
DamonOne
2026-09-01 09:55:30
(1 day ago)
Blocked by OPNsense; 8 hits, proto=tcp, ports=33950
Port Scan
Hacking
π·π΄
DamonOne
2026-09-01 08:22:34
(1 day ago)
Blocked by OPNsense; 5 hits, proto=udp, ports=12053,33950,43529,4401,60105
Port Scan
Hacking
π·π΄
DamonOne
2026-09-01 08:07:20
(1 day ago)
Blocked by OPNsense; 4 hits, proto=udp, ports=12053,43529,4401,57704
Port Scan
Hacking
π¨π³
pengpeng
2026-07-03 21:17:26
(1 month ago)
monitor: on VM-0-7-ubuntu | port: 37410 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporte ...
show more
monitor: on VM-0-7-ubuntu | port: 37410 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π΅π±
sefinek.net
2026-06-25 16:30:58
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from SE.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from SE.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.3 Safari/605.1.15 β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-18 20:39:46
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 16:39:40.894808 2026] [security2:error] [pid 24309:tid 24309] [client 158.173.241.71:52651] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoincasting.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoincasting.com"] [uri "/wp-config.php.bak"] [unique_id "ajRXjGdet8E3LjRFPZZqTQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 11:00:29
(2 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 07:00:23.998647 2026] [security2:error] [pid 15097:tid 15097] [client 158.173.241.71:43911] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||givemethemic.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "givemethemic.org"] [uri "/license.txt"] [unique_id "aiAJRyHW5ld5qGZvlwpEfgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 10:03:52
(2 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 06:03:48.333616 2026] [security2:error] [pid 25806:tid 25806] [client 158.173.241.71:36975] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.difusionens.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.difusionens.org"] [uri "/license.txt"] [unique_id "ah_8BIceBNY-UTqIddqzTwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 08:18:53
(2 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 04:18:46.696196 2026] [security2:error] [pid 27347:tid 27347] [client 158.173.241.71:54605] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||wevfc.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "wevfc.org"] [uri "/license.txt"] [unique_id "ah_jZh_FYQ99ML7ERmMouAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 00:37:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 20:37:45.516553 2026] [security2:error] [pid 15832:tid 15832] [client 158.173.241.71:60519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bikiniadvice.com"] [uri "/wp-config.php.bak"] [unique_id "ah93WbNdxvLCPbZnnStkwAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-01 20:25:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 16:25:53.663004 2026] [security2:error] [pid 18649:tid 18649] [client 158.173.241.71:54013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aholsniffsglue.com"] [uri "/wp-config.php.bak"] [unique_id "ah3q0aMiiJ3AvX8kbTQrfAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-01 14:06:16
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
π¬π§
consul.to
2026-06-01 00:55:46
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
π§πͺ
cmbplf
2026-05-24 12:45:09
(3 months ago)
278 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-23 07:33:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.241.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 03:33:22.205059 2026] [security2:error] [pid 24837:tid 24837] [client 158.173.241.71:30467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "texaslawman.net"] [uri "/wp-config.php.bak"] [unique_id "ahFYQtEYff5s9HbdcXNhSgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack