๐ฉ๐ช
palla89
2026-06-19 14:44:08
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 172.71.99.154 (-)
SQL Injection
๐ณ๐ฑ
homeshowdomain.nl
2026-06-03 21:59:42
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-06-03
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-26 14:52:24
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.99.154 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.99.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 10:52:08.222576 2026] [security2:error] [pid 26980:tid 26986] [client 172.71.99.154:9235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aafmindia.aafm.us"] [uri "/.env.development.local"] [unique_id "ahWzmByiJIRWohethW79RgAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-05-04 20:47:50
(1 month ago)
Unauthorized connection attempt detected from IP address 172.71.99.154 to port 80 [SYD]
Port Scan
๐ฉ๐ช
www.mammazone.it
2026-05-03 23:11:52
(1 month ago)
fabiodirauso.it:443 172.71.99.154 - - [04/May/2026:01:11:49 +0200] "GET /backup.sql HTTP/1.1" 500 41 ...
show more
fabiodirauso.it:443 172.71.99.154 - - [04/May/2026:01:11:49 +0200] "GET /backup.sql HTTP/1.1" 500 4168 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
fabiodirauso.it:443 172.71.99.154 - - [04/May/2026:01:11:49 +0200] "GET /mysqldump.sql HTTP/1.1" 500 4168 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Hacking
๐ฉ๐ช
www.mammazone.it
2026-04-05 01:49:48
(2 months ago)
fabiodirauso.it:443 172.71.99.154 - - [05/Apr/2026:03:49:46 +0200] "GET /.git/HEAD HTTP/1.1" 200 225 ...
show more
fabiodirauso.it:443 172.71.99.154 - - [05/Apr/2026:03:49:46 +0200] "GET /.git/HEAD HTTP/1.1" 200 22527 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
fabiodirauso.it:443 172.71.99.154 - - [05/Apr/2026:03:49:47 +0200] "GET /.git/config HTTP/1.1" 200 18710 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
๐ฉ๐ช
www.mammazone.it
2026-03-31 04:02:58
(2 months ago)
fabiodirauso.it:80 172.71.99.154 - - [31/Mar/2026:06:02:00 +0200] "GET /.git/config HTTP/1.1" 200 18 ...
show more
fabiodirauso.it:80 172.71.99.154 - - [31/Mar/2026:06:02:00 +0200] "GET /.git/config HTTP/1.1" 200 18589 "http://fabiodirauso.it/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
fabiodirauso.it:80 172.71.99.154 - - [31/Mar/2026:06:02:55 +0200] "GET /.env.bak HTTP/1.1" 200 18578 "http://fabiodirauso.it/" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
...
show less
Hacking
๐ฆ๐น
Markus Woegerbauer
2026-02-28 01:11:35
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 172.71.99.154 (NL/Netherlands/-)
SQL Injection
๐ซ๐ท
dynamix
2026-01-09 06:56:06
(5 months ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
el-brujo
2025-12-28 07:01:38
(5 months ago)
28/Dec/2025:08:01:37.602590 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Dec/2025:08:01:37.602590 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.99.154] ModSecurity: Warning. Matched phrase "call_user_func" at ARGS:function. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "295"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: call_user_func found within ARGS:function: call_user_func_array"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "cloudflare.elhacker.net"] [uri "/"] [unique_id "aVDV0ZD26VVeptJU8HTsugABwzo"]
...
show less
Hacking
Web App Attack
๐ฎ๐ช
eyesilyurt
2025-11-29 15:46:47
(6 months ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐บ๐ธ
creations.works
2025-10-08 20:48:08
(8 months ago)
Blocked by UFW on vds [80/tcp]
Source port: 58140
TTL: 54
Packet length: 60
TOS: 0x00
This report w ...
show more
Blocked by UFW on vds [80/tcp]
Source port: 58140
TTL: 54
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
creations.works
2025-10-04 11:22:48
(8 months ago)
Blocked by UFW on vds [80/tcp]
Source port: 9994
TTL: 56
Packet length: 60
TOS: 0x00
This report wa ...
show more
Blocked by UFW on vds [80/tcp]
Source port: 9994
TTL: 56
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-28 13:40:00
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.99.154 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.99.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 28 09:39:56.401833 2025] [security2:error] [pid 1457963:tid 1457963] [client 172.71.99.154:33884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.c2cservices.com"] [uri "/.git/config"] [unique_id "aDcSLGj7PVTVe_eU91Ee1AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-20 05:50:37
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack