π³π±
homeshowdomain.nl
2026-06-05 22:00:35
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-04.
show less
Web App Attack
SSH
Hacking
π¨π
backslash
2026-06-04 17:12:00
(1 week ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
Anonymous
2026-06-04 15:24:26
(1 week ago)
Multiple web server 400 error codes from same source ip
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 11:52:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.243.100.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.243.100.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 07:52:42.044756 2026] [security2:error] [pid 8692:tid 8692] [client 162.243.100.124:51001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aguaflot.aguasolar.com"] [uri "/.env"] [unique_id "aiFnCsRnHgceTha-O4W2NQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
0tsystems
2026-06-04 10:14:51
(1 week ago)
Automated scan detected on 0t.systems: /.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 09:40:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.243.100.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.243.100.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 05:40:49.535269 2026] [security2:error] [pid 20381:tid 20381] [client 162.243.100.124:63552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "admin.casaniagara.com.mx.elpais.mx"] [uri "/.env"] [unique_id "aiFIIQfh1aUUlceIUCRj4AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 09:02:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.243.100.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.243.100.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 05:02:35.296187 2026] [security2:error] [pid 26391:tid 26465] [client 162.243.100.124:50110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tvpin.com"] [uri "/"] [unique_id "aiE_K6s1sS6ukFYFARsFSwAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-04 06:05:50
(1 week ago)
Abuse Detected (3)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-06-04 04:05:52
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 03:42:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.243.100.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.243.100.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 23:42:11.370202 2026] [security2:error] [pid 31259:tid 31276] [client 162.243.100.124:52752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accreditedfinancialanalyst.com"] [uri "/.env"] [unique_id "aiD0EyCA6wG8DelCU3FuQwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
arc21
2026-03-13 09:50:45
(3 months ago)
2026-03-13T09:50:44.688912+00:00 database-prodv1-game kernel: [559377.551382] [UFW BLOCK] IN=eth0 OU ...
show more
2026-03-13T09:50:44.688912+00:00 database-prodv1-game kernel: [559377.551382] [UFW BLOCK] IN=eth0 OUT= MAC=92:00:06:71:5d:8a:d2:74:7f:6e:37:e3:08:00 SRC=162.243.100.124 DST=142.132.169.25 LEN=40 TOS=0x00 PREC=0x00 TTL=239 ID=52224 PROTO=TCP SPT=46574 DPT=9000 WINDOW=1024 RES=0x00 SYN URGP=0
...
show less
Port Scan
πΊπΈ
MPL
2026-03-13 09:48:06
(3 months ago)
tcp/9000
Port Scan
πΊπΈ
xmission.com
2026-03-13 09:32:36
(3 months ago)
Blocked by UFW (TCP on 9000)
Source port: 46574
TTL: 241
Packet length: 40
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 9000)
Source port: 46574
TTL: 241
Packet length: 40
TOS: 0x08
This report (for 162.243.100.124) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
micropedro
2026-03-13 09:24:09
(3 months ago)
3 incidents: port scanning. First: 2026-03-13 05:24, Last: 2026-03-13 05:24 UTC. Triggers: non-publi ...
show more
3 incidents: port scanning. First: 2026-03-13 05:24, Last: 2026-03-13 05:24 UTC. Triggers: non-public-port,non-public-port,firewall-tcp.
show less
Port Scan
π©πͺ
bontekoe.technology
2026-03-13 09:01:02
(3 months ago)
Port scan or Brute-Force detected. (src_port=46574, dst_port=9000)
Brute-Force