๐ฉ๐ช
zupan
2026-08-31 18:24:17
(53 minutes ago)
Blocked by UFW on vps [8443/tcp] | SPT: 14244 | TTL: 57 | LEN: 60 | TOS: 0x00 โข Reported by: github. ...
show more
Blocked by UFW on vps [8443/tcp] | SPT: 14244 | TTL: 57 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-08-31 16:00:43
(3 hours ago)
| A web attack returned code 200 (success).
Web App Attack
Hacking
SQL Injection
๐ฎ๐ฉ
sockominfo
2026-08-31 09:01:02
(10 hours ago)
Active Response: IP 207.175.172.235 Blocked via Firewall Drop, Critical LFI with PHP code injection ...
show more
Active Response: IP 207.175.172.235 Blocked via Firewall Drop, Critical LFI with PHP code injection detected - Basic 2, Possible: LFI with Code Injection / Script Execution via URL (Success: 302)., File/Directory scanning with suspicious user agent Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot).. Threat Score: 9.2/10 (CRITICAL). Confidence: 85%. CVSS v3.1: 10/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 98%. MITRE ATT&CK: T1190 (Exploit Public-Facing Application). Tactic: TA0001. Freshness: Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Brute-Force
๐ฎ๐ฉ
sockominfo
2026-08-31 08:00:28
(11 hours ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-31 07:00:14
(12 hours ago)
Critical LFI with PHP code injection detected - Basic 2. Threat Score: 8.1/10 (HIGH). Reported by Ta ...
show more
Critical LFI with PHP code injection detected - Basic 2. Threat Score: 8.1/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Brute-Force
Anonymous
2026-08-30 02:56:22
(1 day ago)
Blocked by siteaihub.com: live autoban: 10 attacks in 1min
Hacking
Bad Web Bot
๐ต๐ฑ
sefinek.net
2026-08-30 01:40:35
(1 day ago)
Honeypot hit: Empty payload (likely service probe); 9443 [3], 8081 [1], 9090 [1], 9000 [1], 5173 [1] ...
show more
Honeypot hit: Empty payload (likely service probe); 9443 [3], 8081 [1], 9090 [1], 9000 [1], 5173 [1], 2375 [1] TCP
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Port Scan
๐จ๐ฟ
Countryman
2026-08-29 19:44:54
(1 day ago)
IPS detection: Vite.server.fs.deny.raw.Arbitrary.File.Read
Hacking
Anonymous
2026-08-29 19:33:48
(1 day ago)
Blocked by siteaihub.com: auto: matched exact:/.aws/credentials
Hacking
Bad Web Bot
๐ซ๐ท
dynamix
2026-08-29 17:44:50
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 13:33:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 207.175.172.235 (235.172.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.172.235 (235.172.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 09:33:36.892412 2026] [security2:error] [pid 29440:tid 29440] [client 207.175.172.235:16060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.17"] [uri "/.env.local"] [unique_id "apLfsJO7v-AODJgOBqINWgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
a.mohamed.go
2026-08-29 13:12:57
(2 days ago)
207.175.172.235 - - [29/Aug/2026:13:12:57 +0000] "GET /actuator/env HTTP/1.1" 200 10091 "-" "Mozilla ...
show more
207.175.172.235 - - [29/Aug/2026:13:12:57 +0000] "GET /actuator/env HTTP/1.1" 200 10091 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
...
show less
Hacking
Web App Attack
๐ง๐พ
lns.bz
2026-08-29 13:11:16
(2 days ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-08-29 13:01:47
(2 days ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 207.175.172.235 (BE/Belgium/235.172.175.207. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 207.175.172.235 (BE/Belgium/235.172.175.207.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 207.175.172.235 - - [29/Aug/2026:15:01:43 +0200] "GET /media../.env HTTP/1.1" 406 991 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GrokBot/1.0; +https://x.ai/grokbot"
207.175.172.235 - - [29/Aug/2026:15:01:43 +0200] "GET /.env.local HTTP/1.1" 406 991 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:128.15) Gecko/20100101 Firefox/128.15; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
207.175.172.235 - - [29/Aug/2026:15:01:43 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 406 991 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
show less
Port Scan
๐ณ๐ฟ
Antinson
2026-08-29 12:57:43
(2 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot