๐บ๐ธ
antlac1
2026-04-10 01:47:10
(2 months ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
๐ฆ๐น
urnilxfgbez
2026-04-09 22:45:00
(2 months ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
๐บ๐ธ
xmission.com
2026-04-09 08:42:57
(2 months ago)
Blocked by UFW (TCP on 2375)
Source port: 40791
TTL: 47
Packet length: 40
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 2375)
Source port: 40791
TTL: 47
Packet length: 40
TOS: 0x08
This report (for 212.56.54.171) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
EGP Abuse Dept
2026-04-08 07:58:13
(2 months ago)
Scanning for web/db/file exploits on brederaad-010.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ซ๐ท
UM3
2026-04-03 19:46:08
(2 months ago)
Exim Auth Failed
Brute-Force
Anonymous
2026-04-02 21:28:01
(2 months ago)
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-29 11:56:57
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 212.56.54.171 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.56.54.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 06:56:49.784350 2026] [security2:error] [pid 3665325:tid 3665325] [client 212.56.54.171:8857] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ccbank.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ccbank.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aXtLAXT8Hen_jLW8UWo0UwAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ITSNF
2026-01-26 04:15:12
(5 months ago)
FFM Jan 26 05:05:29 websrv01 postfix/submission/smtpd[248388]: warning: unknown[212.56.54.171]: SASL ...
show more
FFM Jan 26 05:05:29 websrv01 postfix/submission/smtpd[248388]: warning: unknown[212.56.54.171]: SASL PLAIN authentication failed: (reason unavailable), [email protected]
Jan 26 05:05:35 websrv01 postfix/submission/smtpd[248388]: warning: unknown[212.56.54.171]: SASL LOGIN authentication failed: (reason unavailable), [email protected]
show less
Email Spam
Brute-Force
๐บ๐ธ
bigscoots.com
2026-01-26 04:14:04
(5 months ago)
(smtpauth) Failed SMTP AUTH login from 212.56.54.171 (US/United States/-): 5 in the last 3600 secs; ...
show more
(smtpauth) Failed SMTP AUTH login from 212.56.54.171 (US/United States/-): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2026-01-25 23:13:33 dovecot_plain authenticator failed for H=([10.2.18.159]) [212.56.54.171]:58774: 535 Incorrect authentication data ([email protected] )
2026-01-25 23:13:39 dovecot_login authenticator failed for H=([10.2.18.159]) [212.56.54.171]:58774: 535 Incorrect authentication data ([email protected] )
2026-01-25 23:13:45 dovecot_plain authenticator failed for H=([10.2.18.159]) [212.56.54.171]:17112: 535 Incorrect authentication data ([email protected] )
2026-01-25 23:13:51 dovecot_login authenticator failed for H=([10.2.18.159]) [212.56.54.171]:17112: 535 Incorrect authentication data ([email protected] )
2026-01-25 23:14:00 dovecot_plain authenticator failed for H=([10.2.18.159]) [212.56.54.171]:14501: 535 Incorrect authentication data ([email protected] )
show less
Brute-Force
SSH
๐จ๐ฆ
Mediashaker
2025-12-19 19:12:07
(6 months ago)
(smtpauth) Failed SMTP AUTH login from 212.56.54.171 (US/United States/-)
Brute-Force
Anonymous
2025-08-04 15:19:24
(10 months ago)
Botnet - login attempts with leaked random user/pass lists
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-21 07:40:06
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 212.56.54.171 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.56.54.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 21 03:40:00.164057 2025] [security2:error] [pid 4546:tid 4546] [client 212.56.54.171:58663] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bickleton.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aH3u0Dk12wv4kj_NOF1BqgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
juguemosalacarioca.com
2025-07-21 06:50:33
(11 months ago)
Multiple HTTP calls attempting to GET resources using common API calls or formats on port 8080
Web App Attack
๐ง๐ช
taivas.nl
2025-07-20 14:32:13
(11 months ago)
Wordpress_xmlrpc_attack
Bad Web Bot
๐ฉ๐ช
Ba-Yu
2025-07-20 04:30:29
(11 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack