πΊπΈ
TPI-Abuse
2025-05-31 02:37:40
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 22:37:37.088562 2025] [security2:error] [pid 1442343:tid 1442343] [client 172.68.238.22:40742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 213.231.7.92 (1+1 hits since last alert)|www.virtualizecr.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.virtualizecr.net"] [uri "/xmlrpc.php"] [unique_id "aDprcU1jqmRnU3-qmaTllQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2025-04-05 12:56:52
(1 year ago)
172.68.238.22 - - [05/Apr/2025:15:56:48 +0300] "GET /wp-includes/SimplePie/about.php HTTP/1.1" 404 1 ...
show more
172.68.238.22 - - [05/Apr/2025:15:56:48 +0300] "GET /wp-includes/SimplePie/about.php HTTP/1.1" 404 196 "-" "-"
172.68.238.22 - - [05/Apr/2025:15:56:49 +0300] "GET /wp-content/banners/about.php HTTP/1.1" 404 196 "-" "-"
...
show less
Web App Attack
πΊπ¦
URAN Publishing Service
2025-03-26 17:08:50
(1 year ago)
172.68.238.22 - - [26/Mar/2025:19:08:49 +0200] "GET /wp-content/fonts/nunito/chosen.php HTTP/1.1" 40 ...
show more
172.68.238.22 - - [26/Mar/2025:19:08:49 +0200] "GET /wp-content/fonts/nunito/chosen.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
172.68.238.22 - - [26/Mar/2025:19:08:49 +0200] "GET /wp-includes/style-engine/chosen.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
...
show less
Web App Attack
Anonymous
2024-11-22 05:40:41
(1 year ago)
Ports: 80,443; Direction: 1; Trigger: LF_CXS
Brute-Force
SSH
Anonymous
2024-11-13 03:06:45
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2024-11-02 05:34:04
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 02 01:33:58.537411 2024] [security2:error] [pid 25896:tid 25896] [client 172.68.238.22:19868] [client 172.68.238.22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virtualizecr.net"] [uri "/.env"] [unique_id "ZyW5xr3byp5bYWeFl6n9rQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-30 04:46:15
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-10-26 02:08:35
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-10-19 03:34:04
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2024-10-14 00:22:16
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 13 20:22:13.319904 2024] [security2:error] [pid 6164:tid 6164] [client 172.68.238.22:57358] [client 172.68.238.22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ard.global"] [uri "/dev/.env"] [unique_id "ZwxkNfFAFe2MAfpsQQQtsAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-24 23:37:07
(1 year ago)
(mod_security) mod_security (id:222050) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:222050) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 24 19:37:01.120675 2024] [security2:error] [pid 600942:tid 600942] [client 172.68.238.22:45846] [client 172.68.238.22] ModSecurity: Access denied with code 403 (phase 2). String match "/wp-admin/admin-ajax.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "3239"] [id "222050"] [rev "8"] [msg "COMODO WAF: Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress (CVE-2014-9734)||ruralcommunitycare.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "ruralcommunitycare.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZvNNHSbd9Z3FJNGdlVxYnAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-13 22:46:16
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 13 18:46:09.726678 2024] [security2:error] [pid 32263:tid 32263] [client 172.68.238.22:34980] [client 172.68.238.22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "safe-secure-protect.com"] [uri "/.env_1"] [unique_id "ZuTAsblQZf2oowP8eKFajgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-12 23:09:24
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.238.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 12 19:09:20.592814 2024] [security2:error] [pid 18417:tid 18417] [client 172.68.238.22:34270] [client 172.68.238.22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sportsbookcommission.com"] [uri "/backend/.env"] [unique_id "ZuN0oBqScGUUkBn8Mu6ZUAAAAF4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
sefinek.net
2024-09-08 00:21:51
(2 years ago)
Blocked by UFW (TCP on port 443).
Source port: 52206
TTL: 51
Packet length: 40
TOS: 0x00
Timestamp: ...
show more
Blocked by UFW (TCP on port 443).
Source port: 52206
TTL: 51
Packet length: 40
TOS: 0x00
Timestamp: 2024-09-08 02:21:51 [Europe/Warsaw]
This report (for 172.68.238.22) was generated by:
https://github.com/sefinek24/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
π΅π±
sefinek.net
2024-09-07 00:57:47
(2 years ago)
Blocked by UFW (TCP on port 443).
Source port: 9478
TTL: 45
Packet length: 40
TOS: 0x08
Timestamp: 2 ...
show more
Blocked by UFW (TCP on port 443).
Source port: 9478
TTL: 45
Packet length: 40
TOS: 0x08
Timestamp: 2024-09-07 02:57:47 [Europe/Warsaw]
This report (for 172.68.238.22) was generated by:
https://github.com/sefinek24/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack