๐ฉ๐ช
SMi-Web
2026-06-27 12:43:14
(2 days ago)
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 24017 | TTL: 57 | LEN: 60 | TOS: 0x00 โข R ...
show more
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 24017 | TTL: 57 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ท๐บ
DZBOT
2026-06-26 22:19:07
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-18 05:42:20
(1 week ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-18 06:42:20 UTC
Log evidence:
06/18/2026-06:42:19.388387 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 172.68.193.192:9901 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-05-16 04:12:17
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 18:59:32
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 14:59:23.356231 2026] [security2:error] [pid 28931:tid 28931] [client 172.68.193.192:9721] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sunshineservicealignment.sunshinenv.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sunshineservicealignment.sunshinenv.com"] [uri "/db_backup.sql"] [unique_id "agDViwbwlOQwlphK9AIqmAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-05-08 21:01:30
(1 month ago)
wordpress scan on 662.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 04:41:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 00:41:18.426589 2026] [security2:error] [pid 22471:tid 22471] [client 172.68.193.192:13029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pennylanefarmsauces.com"] [uri "/.git/config"] [unique_id "afLdbiL4UyiYJ89_Yfg4UgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 22:19:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:19:35.122697 2026] [security2:error] [pid 31754:tid 31754] [client 172.68.193.192:10089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.capecodweddingideas.com"] [uri "/.env.example"] [unique_id "adGOd1bUyyr8vhmhsNKRjgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 20:35:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 16:35:37.366647 2026] [security2:error] [pid 23578:tid 23578] [client 172.68.193.192:11992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vrbsroma.com"] [uri "/.git/refs/heads/master"] [unique_id "adF2GdnX64zo5aBG7kaKeAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-04-04 17:29:38
(2 months ago)
trolling for resource vulnerabilities
Web App Attack
๐ซ๐ท
masterguru
2026-04-03 13:34:57
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-195)
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-02 12:34:37
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 08:34:32.317202 2026] [security2:error] [pid 30477:tid 30477] [client 172.68.193.192:13830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifestyleabs.starrmail.net"] [uri "/.env.dev"] [unique_id "ac5iWGrjCXCeywg0WtnpIwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-31 21:06:21
(2 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 07:59:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 03:59:46.967016 2026] [security2:error] [pid 4523:tid 4523] [client 172.68.193.192:11690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.masalamadrid.com"] [uri "/.git/config"] [unique_id "act-8mMI7ztncqB0FjzJuQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-30 20:08:56
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack