π«π·
omartin
2026-06-11 16:35:27
(2 hours ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
π«π·
omartin
2026-06-06 20:58:52
(4 days ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 18:02:15
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 14:02:10.697426 2026] [security2:error] [pid 7080:tid 7080] [client 172.70.248.99:9576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stewhist.org"] [uri "/.git/config"] [unique_id "aiRgojnr4AdQfV3M2Uif1gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-02 06:05:19
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
π¨π
backslash
2026-05-24 05:21:07
(2 weeks ago)
Bad Web Bot
π«π·
omartin
2026-05-23 08:34:47
(2 weeks ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
π·πΊ
DZBOT
2026-05-20 02:02:33
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π«π·
tavis.page
2026-05-18 03:58:36
(3 weeks ago)
Blocked by UFW on server [443/tcp]
Source port: 11524
TTL: 56
Packet length: 60
TOS: 0x00
This repo ...
show more
Blocked by UFW on server [443/tcp]
Source port: 11524
TTL: 56
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π«π·
omartin
2026-05-16 01:16:03
(3 weeks ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-05-14 01:28:02
(4 weeks ago)
(caddyscan) Scanner path probe from 172.70.248.99 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 172.70.248.99 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.70.248.99 - - [14/May/2026:01:17:38 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.248.99 - - [14/May/2026:01:20:53 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.248.99 - - [14/May/2026:01:27:54 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.248.99 - - [14/May/2026:01:27:58 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.70.248.99 - - [14/May/2026:01:28:00 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-13 11:47:39
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.70.248.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.248.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 07:47:33.138858 2026] [security2:error] [pid 22919:tid 22929] [client 172.70.248.99:13654] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.veganfiestas.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.veganfiestas.com"] [uri "/backup.sql"] [unique_id "agRk1SkrBad4A3IuJdDfHAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-12 17:16:12
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 13:15:56.953366 2026] [security2:error] [pid 10669:tid 10669] [client 172.70.248.99:13235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cortona.ws"] [uri "/.env.dev"] [unique_id "agNgTKwDSkGfAwp6KCxYmgAAABE"], referer: https://www.google.com/search?q=cortona.ws
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π°
sbk97 (https://sayor.net)
2026-05-12 12:48:29
(4 weeks ago)
HTTP attack observed: GET /wp-admin/install.php?step=1 HTTP/1.1 | status=301 | response_size=253
Port Scan
πΊπΈ
TPI-Abuse
2026-05-08 12:52:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 08:52:42.445653 2026] [security2:error] [pid 16956:tid 16956] [client 172.70.248.99:9284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kengarysp.com"] [uri "/.git/config"] [unique_id "af3cmkTa162Ry7f62BxpkwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-05-08 11:46:18
(1 month ago)
Try to access /.git/config
Web App Attack