๐บ๐ธ
TPI-Abuse
2026-07-25 09:58:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 192.111.137.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 192.111.137.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 05:58:30.415975 2026] [security2:error] [pid 2113420:tid 2113420] [client 192.111.137.37:45643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artizandecor.com"] [uri "/.env"] [unique_id "amSIxjTLYkL-ILdiPGStyQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-25 00:05:26
(11 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐น๐ท
neron
2026-07-24 15:30:03
(19 hours ago)
CrowdSec blocked: ssh:bruteforce detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:56:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 192.111.137.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 192.111.137.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:56:03.782665 2026] [security2:error] [pid 3146015:tid 3146015] [client 192.111.137.37:42979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alaskadreamspublishing.com"] [uri "/.env"] [unique_id "amMMg5zds2dPFlamCN49nAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
conrad10781
2026-07-24 05:05:24
(1 day ago)
nginx-dot-env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 02:28:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 192.111.137.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 192.111.137.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 22:28:03.573174 2026] [security2:error] [pid 2891144:tid 2891160] [client 192.111.137.37:32905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arrowsinthequiver.com"] [uri "/.env"] [unique_id "amLNs4QKOjE3o95Cg0U2IgAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 21:17:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 192.111.137.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 192.111.137.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 17:17:39.198009 2026] [security2:error] [pid 961156:tid 961156] [client 192.111.137.37:41183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aholsniffsglue.com"] [uri "/.env"] [unique_id "amKE8wIzJ3PD8YV2ftEShgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-07-10 01:44:19
(2 weeks ago)
Blocked by UFW (TCP on 9101)
Source port: 37462
TTL: 48
Packet length: 60
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 9101)
Source port: 37462
TTL: 48
Packet length: 60
TOS: 0x08
This report (for 192.111.137.37) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
xmission.com
2026-07-09 12:09:59
(2 weeks ago)
Blocked by UFW (TCP on 9101)
Source port: 37118
TTL: 49
Packet length: 60
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 9101)
Source port: 37118
TTL: 49
Packet length: 60
TOS: 0x08
This report (for 192.111.137.37) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
DrLex0
2026-06-30 18:51:49
(3 weeks ago)
Web spam on hidden bait web form
192.111.137.37 443 - [30/Jun/2026:18:51:44 +0000] "GET [redacted] ...
show more
Web spam on hidden bait web form
192.111.137.37 443 - [30/Jun/2026:18:51:44 +0000] "GET [redacted] HTTP/1.1" 200 12580 "[redacted]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
192.111.137.37 443 - [30/Jun/2026:18:51:46 +0000] "GET [redacted] HTTP/1.1" 200 6574 "[redacted]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
192.111.137.37 443 - [30/Jun/2026:18:51:47 +0000] "POST [redacted] HTTP/1.1" 200 6013 "[redacted]" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
192.111.137.37 443 - [30/Jun/2026:18:51:49 +0000] "GET [redacted] HTTP/1.1" 503 8766 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Web Spam
๐บ๐ธ
xmission.com
2026-06-20 06:41:19
(1 month ago)
Blocked by UFW (TCP on 9101)
Source port: 54924
TTL: 49
Packet length: 60
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 9101)
Source port: 54924
TTL: 49
Packet length: 60
TOS: 0x08
This report (for 192.111.137.37) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
BestFans.com
2026-06-07 21:30:31
(1 month ago)
Credential brute-force attacks on webpage logins
Brute-Force
๐ฉ๐ช
Justin F. | AS204464
2026-06-06 17:39:52
(1 month ago)
Honeypot [nx-infrastructure]: Brute-force attack detected on 22/SSH
โข Credentials: ad72d168ba5f:, 33 ...
show more
Honeypot [nx-infrastructure]: Brute-force attack detected on 22/SSH
โข Credentials: ad72d168ba5f:, 33885782a4c5:, e9fbafad3b20:, defb4340eebc:
โข Number of login attempts: 4
โข Client: SSH-2.0-Go
Reported by: Justin F.
show less
Brute-Force
SSH
๐ธ๐ฎ
administrator
2026-06-02 22:12:24
(1 month ago)
2026-06-02 00:03:24,712 fail2ban.actions [1162]: NOTICE [ninjafirewall] Ban 192.111.137.37
2 ...
show more
2026-06-02 00:03:24,712 fail2ban.actions [1162]: NOTICE [ninjafirewall] Ban 192.111.137.37
2026-06-02 00:03:24,712 fail2ban.actions [1162]: NOTICE [ninjafirewall] Ban 192.111.137.37
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
relianoid.com
2026-05-30 17:55:56
(1 month ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam