๐บ๐ธ
billybobby
2026-05-29 08:39:12
(2 weeks ago)
Blocked by UFW [80/tcp] | SPT: 11803 | TTL: 58 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefin ...
show more
Blocked by UFW [80/tcp] | SPT: 11803 | TTL: 58 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
wimaxnz
2026-05-20 05:58:19
(3 weeks ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐ฆ๐บ
oncord
2026-04-10 05:58:00
(2 months ago)
Form spam
Web Spam
๐บ๐ธ
SiliSoftware
2026-03-30 05:25:44
(2 months ago)
/config/env
Web App Attack
Anonymous
2026-03-21 04:19:20
(2 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 09:01:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:01:46.812238 2026] [security2:error] [pid 16762:tid 16762] [client 162.158.154.199:13116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.technologymoods.com"] [uri "/.env.save"] [unique_id "ab0M-i57jkYuFFH4HqfeTAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:39:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:39:13.690853 2026] [security2:error] [pid 31380:tid 31380] [client 162.158.154.199:10623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rooksfamily.com"] [uri "/.env.test"] [unique_id "abz5oQ-SsAj1LIENwkhbcAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:45:09
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:44:59.440024 2026] [security2:error] [pid 7550:tid 7550] [client 162.158.154.199:11920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.uphillfarmvt.com"] [uri "/.env.development.local"] [unique_id "abze2-6Eh2_A-mVW-SehDAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:37:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:36:56.840357 2026] [security2:error] [pid 22291:tid 22318] [client 162.158.154.199:14145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mailme.name"] [uri "/api/.env"] [unique_id "abvf2KwY5tH-ENNCiTWGgQAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:48:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:48:01.744878 2026] [security2:error] [pid 24522:tid 24522] [client 162.158.154.199:13389] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sandiegoautostarsmog.smogsandiego.com"] [uri "/app/.env"] [unique_id "abvUYWYCCsAgYe7rVFyJ7wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:11:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:10:59.274317 2026] [security2:error] [pid 13924:tid 13924] [client 162.158.154.199:11628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.phenomenalcattery.com"] [uri "/.env1"] [unique_id "abvLs6mjlM6L2TRX38lzRwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:55:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:55:13.595519 2026] [security2:error] [pid 2579:tid 2579] [client 162.158.154.199:10281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.auditleverage.com"] [uri "/var/www/html/.env"] [unique_id "abvIAav1Fe7oszvs8VCrXQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:11:20
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:11:11.596611 2026] [security2:error] [pid 26452:tid 26452] [client 162.158.154.199:12068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.title36.com"] [uri "/config/.env.local"] [unique_id "abu9rwdvYbC5Qx3U5ruKkgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 08:41:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:41:17.224658 2026] [security2:error] [pid 5468:tid 5468] [client 162.158.154.199:10488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.drumez.com"] [uri "/app/.env"] [unique_id "abu2rR6FH-V8WCCrT1kZJAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 08:26:09
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:26:00.728385 2026] [security2:error] [pid 28538:tid 28538] [client 162.158.154.199:11563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.maycockfamily.com"] [uri "/srv/.env"] [unique_id "abuzGLh8AwIt_mrW88O5pQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack