Anonymous
2025-10-29 09:33:23
(11 months ago)
Aggressive web scan
Web App Attack
๐ต๐ฑ
Niko's Stuff
2025-09-16 20:45:18
(1 year ago)
[1x] F2B | Suspicious activity blocked on: ufw | BanTime: 604800s | Suspicious TCP packet from 172.7 ...
show more
[1x] F2B | Suspicious activity blocked on: ufw | BanTime: 604800s | Suspicious TCP packet from 172.71.130.141:53642 โ port 8443 | TTL: 55, LEN: 60, TOS: 0x00, PREC: 0x00, Interface: eth0
show less
Port Scan
Anonymous
2025-08-24 01:25:14
(1 year ago)
[Sun Aug 24 03:25:13.008354 2025] [authz_core:error] [pid 28502] [client 172.71.130.141:36654] AH016 ...
show more
[Sun Aug 24 03:25:13.008354 2025] [authz_core:error] [pid 28502] [client 172.71.130.141:36654] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Aug 24 03:25:13.028896 2025] [authz_core:error] [pid 28502] [client 172.71.130.141:36654] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Aug 24 03:25:13.048604 2025] [authz_core:error] [pid 28502] [client 172.71.130.141:36654] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2025-08-23 15:33:36
(1 year ago)
[Sat Aug 23 17:33:35.508469 2025] [authz_core:error] [pid 12944] [client 172.71.130.141:63694] AH016 ...
show more
[Sat Aug 23 17:33:35.508469 2025] [authz_core:error] [pid 12944] [client 172.71.130.141:63694] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Aug 23 17:33:35.532132 2025] [authz_core:error] [pid 12944] [client 172.71.130.141:63694] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Aug 23 17:33:35.555011 2025] [authz_core:error] [pid 12944] [client 172.71.130.141:63694] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2025-08-23 14:14:45
(1 year ago)
[Sat Aug 23 16:14:44.546176 2025] [authz_core:error] [pid 10356] [client 172.71.130.141:15462] AH016 ...
show more
[Sat Aug 23 16:14:44.546176 2025] [authz_core:error] [pid 10356] [client 172.71.130.141:15462] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Aug 23 16:14:44.575512 2025] [authz_core:error] [pid 10356] [client 172.71.130.141:15462] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Aug 23 16:14:44.605086 2025] [authz_core:error] [pid 10356] [client 172.71.130.141:15462] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2025-08-12 21:47:12
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
๐บ๐ธ
mawan
2025-08-10 02:49:31
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
no1knows.com
2025-07-28 18:55:47
(1 year ago)
2025/07/28 19:55:44 [error] 3281773#3281773: *272384 FastCGI sent in stderr: "Primary script unknown ...
show more
2025/07/28 19:55:44 [error] 3281773#3281773: *272384 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.130.141, server: _, request: "GET /info.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "www.no1knows.com"
2025/07/28 19:55:44 [error] 3281773#3281773: *272384 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.130.141, server: _, request: "GET /phpinfo.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "www.no1knows.com"
2025/07/28 19:55:44 [error] 3281773#3281773: *272384 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 172.71.130.141, server: _, request: "GET /lara/phpinfo.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "www.no1knows.com"
...
show less
Brute-Force
Bad Web Bot
Anonymous
2025-07-25 18:35:09
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-06-12 06:20:07
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 12 02:20:00.668703 2025] [security2:error] [pid 1778945:tid 1778945] [client 172.71.130.141:32716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avaliantlife.com"] [uri "/.git/HEAD"] [unique_id "aEpxkMLmQSYj7oXhh8B7ggAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 12:03:48
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 08:03:43.442316 2025] [security2:error] [pid 2754275:tid 2754275] [client 172.71.130.141:23350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pixacast.com"] [uri "/portal/.env"] [unique_id "aDxBn_KVLABtv_cS6_XIGgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
creations.works
2025-05-15 02:30:57
(1 year ago)
Blocked by UFW on vds [80/tcp]
Source port: 28218
TTL: 57
Packet length: 60
TOS: 0x00
This report w ...
show more
Blocked by UFW on vds [80/tcp]
Source port: 28218
TTL: 57
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-06 23:00:12
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 19:00:04.462045 2025] [security2:error] [pid 2608943:tid 2608943] [client 172.71.130.141:51690] [client 172.71.130.141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hollyranch.com"] [uri "/.env"] [unique_id "aBqUdFq_fLPRqX6iTnhWWAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-04 08:13:16
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-05-03 06:04:26
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH