๐ง๐ช
madeit
2026-08-20 11:20:31
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 01:05:47
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:05:43.006239 2026] [security2:error] [pid 14242:tid 14242] [client 162.158.189.87:10416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.americanexportimport.com"] [uri "/.git/config"] [unique_id "aoOv59GHCIBn23NaZhqZjwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-17 22:00:39
(6 days ago)
Auto-ban: >3000 req/min op 2026-08-17
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-17 06:34:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:34:07.794383 2026] [security2:error] [pid 21623:tid 21623] [client 162.158.189.87:12517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.francisfell.com"] [uri "/.git/config"] [unique_id "aoKrX5PuFFNBFRUCSvGnHgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:50:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:50:23.426748 2026] [security2:error] [pid 30593:tid 30593] [client 162.158.189.87:11141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.meridianranchdrc.org"] [uri "/.git/config"] [unique_id "aoJ27-Oujqptc56xd7GWZgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 01:24:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:24:12.230217 2026] [security2:error] [pid 27557:tid 27557] [client 162.158.189.87:13782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.synergystudios.org"] [uri "/.git/config"] [unique_id "aoJivOCOvz1Uhz8tSJHMeQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:58:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.189.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:58:15.105473 2026] [security2:error] [pid 16329:tid 16329] [client 162.158.189.87:13577] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rjdyckarchitect.com"] [uri "/.git/config"] [unique_id "aoF7pwh-1Mvvhapq_5rSOgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-07 17:35:39
(2 weeks ago)
Web App Attack
๐ฎ๐น
IRT@Unisi
2026-02-27 18:25:15
(5 months ago)
anomaly:tcp_dst_session,1001>threshold1000,repeats77timessincelastlog
DDoS Attack
๐บ๐ธ
mawan
2025-09-22 09:00:02
(11 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2025-09-14 16:36:46
(11 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ช๐ธ
el-brujo
2025-08-27 04:43:31
(11 months ago)
27/Aug/2025:06:43:31.579665 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
27/Aug/2025:06:43:31.579665 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 162.158.189.87] ModSecurity: Warning. Matched phrase "Dockerfile" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: Dockerfile found within REQUEST_FILENAME: /cursos/udemy - docker mastery with kubernetes swarm from a docker captain/21 - devops and docker clips/168 - entrypoint vs cmd whats the difference in dockerfiles italian.srt"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "el-hacker.org"] [uri "/Cursos/Udemy - Docker Mastery with Kubernetes Swarm from a Docker Captain/21 - DevOps and Docker Clips/168 - ENTRYPOINT vs CMD whats the difference in Do
...
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2025-07-22 15:16:41
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
creations.works
2025-05-25 14:01:31
(1 year ago)
Blocked by UFW on vds [80/tcp]
Source port: 55824
TTL: 53
Packet length: 60
TOS: 0x00
This report w ...
show more
Blocked by UFW on vds [80/tcp]
Source port: 55824
TTL: 53
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-09 15:52:45
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack