๐บ๐ธ
nowyouknow
2026-07-22 12:20:40
(4 hours ago)
Phishing
Web Spam
๐ธ๐ฌ
securejdprop
2026-07-21 03:26:21
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor E ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor Exit Node Traffic group 80).
show less
Hacking
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-07-21 02:47:12
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor R ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 77).
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 14:26:00
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 204.8.96.71 (tor48.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:210730) triggered by 204.8.96.71 (tor48.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 10:25:52.388536 2026] [security2:error] [pid 18216:tid 18216] [client 204.8.96.71:32912] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.nationalccl.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.nationalccl.com"] [uri "/blog/wp-json/oembed/1.0/biztalkhttpreceive.dll"] [unique_id "al4v8FMhImnXxRy9Wi8dXwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 17:44:49
(2 days ago)
(mod_security) mod_security (id:210831) triggered by 204.8.96.71 (tor48.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:210831) triggered by 204.8.96.71 (tor48.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 13:44:45.967484 2026] [security2:error] [pid 1996547:tid 1996547] [client 204.8.96.71:34764] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.mvpbees.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.mvpbees.com"] [uri "/robots.txt"] [unique_id "al0NDQdUxl4empbHJp8jaAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 10:05:09
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 204.8.96.71 (tor48.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:210831) triggered by 204.8.96.71 (tor48.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 06:05:05.190350 2026] [security2:error] [pid 1917:tid 1917] [client 204.8.96.71:53540] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.register-yacht-croatia.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.register-yacht-croatia.com"] [uri "/robots.txt"] [unique_id "alyhUV1NRZiAJFjvhec5OgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2026-07-18 12:07:21
(4 days ago)
Phishing
Web Spam
Anonymous
2026-07-17 10:08:46
(5 days ago)
Detected by CrowdSec: crowdsecurity/http-bad-user-agent
Web App Attack
๐บ๐ธ
xmission.com
2026-07-13 20:02:10
(1 week ago)
Blocked by UFW (TCP on 43704)
Source port: 445
TTL: 54
Packet length: 76
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 43704)
Source port: 445
TTL: 54
Packet length: 76
TOS: 0x08
This report (for 204.8.96.71) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฆ๐บ
screwlooseit.com.au
2026-07-10 10:06:50
(1 week ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
US/United States/tor48.quintex.com
Web App Attack
๐ซ๐ท
dynamix
2026-07-09 23:42:13
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-07-08 10:58:37
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
IVski
2026-07-06 14:44:13
(2 weeks ago)
IVski WAF | Affiliate/scam landing path scan
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-07-02 12:01:16
(2 weeks ago)
2026-07-02 04:01:03,606 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.71
2026-07-02 ...
show more
2026-07-02 04:01:03,606 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.71
2026-07-02 07:00:30,845 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.71
2026-07-02 10:00:23,950 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.71
2026-07-02 13:00:16,934 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.71
2026-07-02 15:01:01,307 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.71
show less
Brute-Force
๐บ๐ธ
canine.tools
2024-12-10 13:48:59
(1 year ago)
[fail2ban Auto Report] searxng search spam abuse
Port Scan
Brute-Force