๐ช๐ธ
Z|ntrueรฑigO
2026-07-21 21:56:57
(13 hours ago)
Auto-report. Hits=1, Ports=443, Country=-.
Brute-Force
๐ณ๐ฑ
Selckie
2026-07-07 09:55:17
(2 weeks ago)
fail2ban: NGINX unusual impact
Web App Attack
๐ฐ๐ท
enp0s1
2026-06-16 05:43:02
(1 month ago)
Auto-reported by Fail2Ban (UFW Block, Port Scan)
Port Scan
๐ง๐ช
sid3windr
2026-06-12 01:17:42
(1 month ago)
GET /.git/HEAD (Tarpitted for 1d15h8m26s, wasted 8.06MB)
Web App Attack
๐ฆ๐น
urnilxfgbez
2026-06-10 22:45:00
(1 month ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
๐ง๐ท
diego
2026-06-10 15:00:20
(1 month ago)
[probe-44-49] 2026-06-10 14:42:43, Client: 172.212.164.19, Protocol: 6, Unauthorized activity to HTT ...
show more
[probe-44-49] 2026-06-10 14:42:43, Client: 172.212.164.19, Protocol: 6, Unauthorized activity to HTTP: POST /___proxy_subdomain_whm/login/
show less
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-06-10 14:34:24
(1 month ago)
172.212.164.19 - - [10/Jun/2026:11:34:19 -0300] "GET /.git/HEAD HTTP/1.1" 404 118 "-" "Mozilla/5.0 ( ...
show more
172.212.164.19 - - [10/Jun/2026:11:34:19 -0300] "GET /.git/HEAD HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
172.212.164.19 - - [10/Jun/2026:11:34:20 -0300] "GET /.git/config HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15"
172.212.164.19 - - [10/Jun/2026:11:34:21 -0300] "GET /.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
172.212.164.19 - - [10/Jun/2026:11:34:22 -0300] "GET /.env.local HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
172.212.164.19 - - [10/Jun/2026:11:34:23 -0300] "GET /.env.production HTTP/1.1" 404 118 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 14:08:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.212.164.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.212.164.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 10:08:03.849444 2026] [security2:error] [pid 19076:tid 19076] [client 172.212.164.19:24075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.177"] [uri "/.git/config"] [unique_id "ailvwzy1Rg8sTkZt101oDgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-06-10 13:04:37
(1 month ago)
URL Probing: /.env
Web App Attack
๐น๐ญ
Sawasdee
2026-06-10 12:51:11
(1 month ago)
Unwanted checking 80 or 443 port
...
Bad Web Bot
๐บ๐ธ
masterguru
2026-06-10 12:45:28
(1 month ago)
Host header is a numeric IP address. Pattern match "^ (920350-166)
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-10 11:39:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.212.164.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.212.164.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 07:39:16.139951 2026] [security2:error] [pid 20424:tid 20424] [client 172.212.164.19:24462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.243"] [uri "/.git/HEAD"] [unique_id "ailM5GpDBJsw73WsmFaCZQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
thororen
2026-06-10 11:38:20
(1 month ago)
Blocked by UFW [2087/tcp]
Source port: 24474
TTL: 44
Packet length: 60
TOS: 0x00
This report was ge ...
show more
Blocked by UFW [2087/tcp]
Source port: 24474
TTL: 44
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-10 10:37:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.212.164.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.212.164.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 06:37:47.537079 2026] [security2:error] [pid 5971:tid 5971] [client 172.212.164.19:23713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.136"] [uri "/.git/HEAD"] [unique_id "aik-e-q2UpA0tnSRv3UV-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-06-10 10:12:52
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection