π§π·
dominioz
2026-05-31 10:32:42
(4 days ago)
2026-05-31 10:31:49 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64 ...
show more
2026-05-31 10:31:49 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 - 301 566
2026-05-31 10:31:49 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 - 301 465
2026-05-31 10:31:50 GET /err/ 404;https://menumais.com.br:443/.git/config - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 https://menumais.com.br/.git/config 302 707
2026-05-31 10:31:50 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 http://menumais.com.br/.git/config 301 566
...
show less
Web App Attack
Anonymous
2026-05-31 04:32:10
(4 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π§π·
vfAcceloReporter
2026-05-31 00:32:42
(4 days ago)
159.203.63.249 - - [30/May/2026:21:32:42 -0300] "POST //vendor/phpunit/phpunit/src/Util/PHP/eval-std ...
show more
159.203.63.249 - - [30/May/2026:21:32:42 -0300] "POST //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Exploited Host
π¬π§
consul.to
2026-05-30 21:09:55
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-05-30 18:35:21
(4 days ago)
159.203.63.249 - - [30/May/2026:15:35:20 -0300] "GET /.git/config HTTP/1.1" 403 829 "https://blogman ...
show more
159.203.63.249 - - [30/May/2026:15:35:20 -0300] "GET /.git/config HTTP/1.1" 403 829 "https://blogmania.com.br/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
159.203.63.249 - - [30/May/2026:15:35:20 -0300] "GET /.git/config HTTP/1.1" 403 829 "https://blogmania.com.br/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
...
show less
Port Scan
π§π·
dominioz
2026-05-30 18:33:40
(4 days ago)
2026-05-30 18:32:51 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64 ...
show more
2026-05-30 18:32:51 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 - 301 485
2026-05-30 18:32:52 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 - 404 25658
2026-05-30 18:32:52 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 http://blog.juliofantasma.com.br/.git/config 404 25658
...
show less
Web App Attack
π§π·
vfAcceloReporter
2026-05-30 17:28:46
(4 days ago)
159.203.63.249 - - [30/May/2026:14:28:45 -0300] "GET /.git/config HTTP/1.1" 404 124 "-" "Mozilla/5.0 ...
show more
159.203.63.249 - - [30/May/2026:14:28:45 -0300] "GET /.git/config HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
159.203.63.249 - - [30/May/2026:14:28:45 -0300] "GET /.git/config HTTP/1.1" 404 124 "http://bertolini.vieirafilho.com.br/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
159.203.63.249 - - [30/May/2026:14:28:45 -0300] "GET //assets/plugins/jQuery-File-Upload/server/php/ HTTP/1.1" 400 90 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
159.203.63.249 - - [30/May/2026:14:28:45 -0300] "GET //assets/admin/bower_components/jquery.filer/php/readme.txt HTTP/1.1" 400 90 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
159.203.63.249 - - [30/May/2026:14:28:45 -0300] "POST //ALFA_DATA/
...
show less
Brute-Force
Web App Attack
Exploited Host
π§π·
dominioz
2026-05-30 17:13:21
(4 days ago)
2026-05-30 16:26:35 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64 ...
show more
2026-05-30 16:26:35 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 - 301 475
2026-05-30 16:26:35 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 - 301 474
2026-05-30 16:26:36 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 http://balbinomoveis.com.br/.git/config 301 474
2026-05-30 16:26:36 GET /.git/config - - 159.203.63.249 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/132.0.0.0+Safari/537.36 https://balbinomoveis.com.br/.git/config 404 34424
...
show less
Web App Attack
πΊπΈ
agenciahypelab.com.br
2026-05-30 17:12:49
(4 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
Anonymous
2026-05-30 15:43:09
(5 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
π«π·
masterguru
2026-04-30 02:56:31
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 159.203.63.249 (CA/Canada/-): 2 in th ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 159.203.63.249 (CA/Canada/-): 2 in the last 3600 secs (0-196)
show less
Hacking
πΊπΈ
xmission.com
2026-04-30 02:27:49
(1 month ago)
Blocked by UFW (TCP on 443)
Source port: 61000
TTL: 241
Packet length: 44
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 443)
Source port: 61000
TTL: 241
Packet length: 44
TOS: 0x08
This report (for 159.203.63.249) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
π±π°
csoc
2022-10-21 05:32:46
(3 years ago)
Long Request
Web App Attack
πΏπ¦
IrisFlower
2022-10-21 03:19:26
(3 years ago)
Unauthorized connection attempt detected from IP address 159.203.63.249 to port 80 [J]
Port Scan
Hacking
πΏπ¦
IrisFlower
2022-10-21 03:03:15
(3 years ago)
Unauthorized connection attempt detected from IP address 159.203.63.249 to port 443 [J]
Port Scan
Hacking