Anonymous
2026-09-12 05:50:08
(17 hours ago)
denied traffic to a honeypot network. destination port 53.
Port Scan
Hacking
🇷🇸
Scan
2026-08-26 02:00:13
(2 weeks ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
🇮🇳
evicky2002
2026-08-24 05:20:21
(2 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=92, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
iNetWorker
2026-08-13 12:57:21
(4 weeks ago)
trying to access non-authorized port
Port Scan
🇺🇸
TPI-Abuse
2026-06-04 09:40:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 05:40:55.271748 2026] [security2:error] [pid 27873:tid 27873] [client 185.132.187.134:51827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schonar.com"] [uri "/.git/HEAD"] [unique_id "aiFIJ3jVdbakXMA55YNj7wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-04 09:14:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 05:14:36.994705 2026] [security2:error] [pid 15453:tid 15453] [client 185.132.187.134:44833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samuelpaley.com"] [uri "/.git/HEAD"] [unique_id "aiFB_PpIrNtLuB-I0Wr9nwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-04 08:42:19
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 04:42:14.665805 2026] [security2:error] [pid 6431:tid 6431] [client 185.132.187.134:21053] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aam-artists.com"] [uri "/.git/HEAD"] [unique_id "aiE6Zhh-Pln18_8wiOlJjwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-06-04 08:06:58
(3 months ago)
Abuse Detected (4)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-04 08:02:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 04:02:04.742133 2026] [security2:error] [pid 16866:tid 16896] [client 185.132.187.134:33399] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koublacat.com"] [uri "/.git/config"] [unique_id "aiEw_B5pvNPppI9GXmixMQAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-04 07:43:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 03:43:46.731016 2026] [security2:error] [pid 32201:tid 32201] [client 185.132.187.134:30539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jetzilla.com"] [uri "/.git/HEAD"] [unique_id "aiEssrML9er4UbuMugVy0AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
sthoyer.de
2026-05-10 03:02:49
(4 months ago)
May 10 05:02:45 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
May 10 05:02:45 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=185.132.187.134 DST=173.212.223.67 LEN=40 TOS=0x00 PREC=0x00 TTL=243 ID=59208 PROTO=TCP SPT=24627 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0
...
show less
Port Scan
🇫🇷
EDSL
2026-05-10 02:33:03
(4 months ago)
[SRV-VPN1] Blocked by SysWarden Firewall (RDP/VNC Attack Port 3389)
Brute-Force
Port Scan
🇩🇪
zupan
2026-05-10 01:28:40
(4 months ago)
Blocked by UFW on vps [3389/tcp] | SPT: 22419 | TTL: 242 | LEN: 40 | TOS: 0x00 • Reported by: github ...
show more
Blocked by UFW on vps [3389/tcp] | SPT: 22419 | TTL: 242 | LEN: 40 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇫🇷
evvsk
2026-05-10 01:25:40
(4 months ago)
3389/tcp
Port Scan
🇫🇷
centurion
2026-05-10 00:37:37
(4 months ago)
Unauthorized attempt on uptime [3389/tcp]
Source port: 20910
TTL: 243
Packet length: 40
TOS: 0x00
ht ...
show more
Unauthorized attempt on uptime [3389/tcp]
Source port: 20910
TTL: 243
Packet length: 40
TOS: 0x00
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan