๐ซ๐ท
Kejult
2026-10-05 04:46:11
(1 day ago)
Honeypot Finding: repeated TCP service probing on TCP/22 (SSH); 4 application-level events across 4 ...
show more
Honeypot Finding: repeated TCP service probing on TCP/22 (SSH); 4 application-level events across 4 source port(s). Sensor(s): Cowrie.
show less
Port Scan
๐ฉ๐ช
Vegascosmetics
2026-10-05 00:21:05
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 67>=65, Abuse 64, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
Admins@FBN
2026-10-04 01:55:46
(2 days ago)
FW-PortScan: Traffic Blocked srcport=39141 dstport=22
Port Scan
Hacking
SSH
๐บ๐ธ
xmission.com
2026-10-03 22:12:19
(2 days ago)
Blocked by UFW (TCP on 23)
Source port: 53773
TTL: 48
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 23)
Source port: 53773
TTL: 48
Packet length: 60
TOS: 0x00
This report (for 213.230.86.219) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-03 12:56:55
(3 days ago)
(mod_security) mod_security (id:210350) triggered by 213.230.86.219 (219.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.86.219 (219.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 08:56:48.739963 2026] [security2:error] [pid 16149:tid 16149] [client 213.230.86.219:23051] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||wildcomaui.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wildcomaui.com"] [uri "/"] [unique_id "asD7kHlPGM7BG2j99j2GXgAAACY"], referer: https://bestlinkbuildingstrategies.space/dir/professional-seo-links-232330
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:13:28
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 213.230.86.219 (219.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.86.219 (219.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:13:23.173467 2026] [security2:error] [pid 1506:tid 1506] [client 213.230.86.219:27387] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.concentricsteel.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.concentricsteel.com"] [uri "/"] [unique_id "ar3P03bqzivfyAs3kPBlrgAAAAE"], referer: https://bulkbacklinkmaker.website/dir/editorial-seo-backlinks-44016
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-30 23:03:10
(5 days ago)
tcp/22 (2 or more attempts)
Port Scan
๐ฉ๐ฐ
powerhostingdk
2026-09-30 13:38:27
(6 days ago)
[mailserver] CrowdSec detected crowdsecurity/postscreen-rbl (1 events). Automated abuse report.
Email Spam
Brute-Force
Anonymous
2026-09-30 13:03:16
(6 days ago)
Postfix SASL brute-force authentication attempt
Brute-Force
Anonymous
2026-09-30 08:37:44
(6 days ago)
denied traffic to a honeypot network. destination port 23.
Port Scan
Hacking
๐ณ๐ฑ
soverin
2026-09-29 14:42:05
(1 week ago)
spam
Email Spam
Anonymous
2026-09-27 19:40:10
(1 week ago)
denied Telnet access attempt. destination port 23.
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-27 07:53:46
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 213.230.86.219 (219.64.uzpak.uz): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 213.230.86.219 (219.64.uzpak.uz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 03:53:42.028770 2026] [security2:error] [pid 11642:tid 11642] [client 213.230.86.219:41766] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||solderhead.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "solderhead.com"] [uri "/"] [unique_id "arjLhi3tHbsoxJn78jTsIwAAABQ"], referer: https://sitecheckerfree.online/dir/backlink-seo-experts-193987
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-09-21 10:28:47
(2 weeks ago)
NOQUEUE - IP: 213.230.86.219 - Sep 21 12:28:46 plesk postfix/smtpd[2680511]: NOQUEUE: reject: RCPT ...
show more
NOQUEUE - IP: 213.230.86.219 - Sep 21 12:28:46 plesk postfix/smtpd[2680511]: NOQUEUE: reject: RCPT from unknown[213.230.86.219]: 554 5.7.1 Service unavailable; Client host [213.230.86.219] blocked using dnsbl-1.uceprotect.net; IP 213.230.86.219 is UCEPROTECT-Level 1 listed. See http://www.uceprotect.net/rblcheck.php?ipr=213.230.86.219; from=<REDACTED@REDACTED> to=<REDACTED@REDACTED> proto=ESMTP helo=<[213.230.86.219]>
show less
Email Spam
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-20 11:01:26
(2 weeks ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Bad Web Bot