Anonymous
2026-10-11 02:07:57
(9 hours ago)
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 25900 | TTL: 57 | LEN: 60 | TOS: 0x00 β’ R ...
show more
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 25900 | TTL: 57 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-10-10 22:37:31
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.246.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.246.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:37:26.249210 2026] [security2:error] [pid 1183:tid 1183] [client 172.71.246.242:12324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomasmichaelrussell.com"] [uri "/.git/config"] [unique_id "asq-Ju7wT7DLqN90WDEPSAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 18:07:16
(2 days ago)
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 21822 | TTL: 57 | LEN: 60 | TOS: 0x00 β’ R ...
show more
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 21822 | TTL: 57 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-10-03 23:38:21
(1 week ago)
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 24180 | TTL: 57 | LEN: 60 | TOS: 0x00 β’ R ...
show more
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 24180 | TTL: 57 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π§πͺ
madeit
2026-08-25 17:18:00
(1 month ago)
Web App Attack
Anonymous
2026-08-11 14:50:31
(1 month ago)
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 24228 | TTL: 57 | LEN: 60 | TOS: 0x00 β’ R ...
show more
Blocked by firewall on hugin [8443/tcp] | Rule: UFW | SPT: 24228 | TTL: 57 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π·πΊ
DZBOT
2026-08-07 16:28:21
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π§πͺ
madeit
2026-08-05 06:23:05
(2 months ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-03 22:46:30
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.246.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.246.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 17:46:24.980880 2026] [security2:error] [pid 6158:tid 6158] [client 172.71.246.242:11313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sutherlandyogastudio.com"] [uri "/.git/config"] [unique_id "aadkwHXWVXXyDWchVUwQ-wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-01 06:28:36
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.246.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.246.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 01:28:30.609713 2026] [security2:error] [pid 4285:tid 4285] [client 172.71.246.242:12827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifeinsmoke.com"] [uri "/.git/config"] [unique_id "aaPcjo0qsNzFeTaQLR04ewAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-01 03:19:51
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.246.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.246.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 22:19:44.381767 2026] [security2:error] [pid 25031:tid 25063] [client 172.71.246.242:11991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janetkeeton.com"] [uri "/.git/config"] [unique_id "aaOwUEmgxDy1z-je3OsQVwAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-01-09 23:05:59
(9 months ago)
Auto-ban: >3000 req/min op 2026-01-09
Hacking
Web App Attack
SSH
π©πͺ
403veli
2026-01-03 04:26:20
(9 months ago)
Confirmed malicious activity observed via T-Pot honeypot Observed 25 events on port 80 (unknown) fro ...
show more
Confirmed malicious activity observed via T-Pot honeypot Observed 25 events on port 80 (unknown) from 2026-01-03T04:26:20+00:00 to 2026-01-03T04:27:30.136000+00:00. Sample: {"src_ip": "172.71.246.242", "src_port": 31331, "dest_port": 80}
show less
Port Scan
πΊπΈ
COMPLEX
2025-12-31 15:34:57
(9 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
Anonymous
2025-12-27 13:32:39
(9 months ago)
[Sat Dec 27 14:32:38.212270 2025] [authz_core:error] [pid 10892] [client 172.71.246.242:13472] AH016 ...
show more
[Sat Dec 27 14:32:38.212270 2025] [authz_core:error] [pid 10892] [client 172.71.246.242:13472] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.co.uk/
[Sat Dec 27 14:32:38.527270 2025] [authz_core:error] [pid 10892] [client 172.71.246.242:13472] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://duckduckgo.com/
[Sat Dec 27 14:32:38.841023 2025] [authz_core:error] [pid 10892] [client 172.71.246.242:13472] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.co.uk/
...
show less
Web App Attack