๐บ๐ธ
xmission.com
2026-08-27 15:00:45
(7 hours ago)
Blocked by UFW (TCP on 52363)
Source port: 56824
TTL: 47
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 52363)
Source port: 56824
TTL: 47
Packet length: 60
TOS: 0x08
This report (for 213.152.186.116) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฒ๐พ
Rizzy
2026-08-23 09:01:17
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
s@ch@
2026-08-23 08:00:01
(4 days ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-23 07:53:32
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 213.152.186.116 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:949110) triggered by 213.152.186.116 (connected-by.global-layer.com): N in the last X secs
show less
Web App Attack
๐ง๐ช
cmbplf
2026-08-23 07:41:01
(4 days ago)
101 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-08-23 07:16:55
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-23 04:51:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.152.186.116 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.186.116 (connected-by.global-layer.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 00:51:42.077101 2026] [security2:error] [pid 2129:tid 2165] [client 213.152.186.116:50978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.teritemme.com"] [uri "/wp-config.php.save"] [unique_id "aop8XjNoT0IUxxwJCwdfsQAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-08-23 02:56:48
(4 days ago)
Suspicious URL access.
Web App Attack
๐ซ๐ท
Octopuce
2026-08-23 02:54:15
(4 days ago)
Aggressive web search of vulnerable pages: /.env~ /.env.bak /.env.swp /.env /.env.backup /.env.old / ...
show more
Aggressive web search of vulnerable pages: /.env~ /.env.bak /.env.swp /.env /.env.backup /.env.old /.env.save /.env.example /.env.development / ...
show less
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-23 01:18:11
(4 days ago)
*Port Scan* detected from 213.152.186.116 (NL/The Netherlands/-/-/connected-by.global-layer.com).
Port Scan
๐ฌ๐ง
Apache
2026-08-22 22:56:44
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.152.186.116 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.186.116 (connected-by.global-layer.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-22 20:48:48
(5 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.txt (+2 more)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 20:24:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 213.152.186.116 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 213.152.186.116 (connected-by.global-layer.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:23:59.867417 2026] [security2:error] [pid 2266:tid 2266] [client 213.152.186.116:35830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.newcastle91.org"] [uri "/wp-config.php.old"] [unique_id "aooFX54xfYb6QnWXQjS1_gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-08-22 17:17:12
(5 days ago)
www.longfisolutions.com 213.152.186.116 - - [22/Aug/2026:12:17:05 -0500] "GET /wp-config.txt HTTP/2. ...
show more
www.longfisolutions.com 213.152.186.116 - - [22/Aug/2026:12:17:05 -0500] "GET /wp-config.txt HTTP/2.0" 404 20257 "-" "Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" MISS
www.longfisolutions.com 213.152.186.116 - - [22/Aug/2026:12:17:11 -0500] "GET /wp-config-backup.txt HTTP/2.0" 404 20257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" MISS
www.longfisolutions.com 213.152.186.116 - - [22/Aug/2026:12:17:11 -0500] "GET /wp-config.backup HTTP/2.0" 404 20257 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.4.16" MISS
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 13:44:18
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 213.152.186.116 (connected-by.global-layer.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 213.152.186.116 (connected-by.global-layer.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:44:10.565184 2026] [security2:error] [pid 25303:tid 25303] [client 213.152.186.116:58876] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.instalatoribucuresti.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.instalatoribucuresti.com"] [uri "/wp-config.backup"] [unique_id "aomnqtqE3HfAlpfbMqzLSwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack