๐ฎ๐ณ
evicky2002
2026-07-08 06:29:13
(2 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-05-20 07:46:40
(4 months ago)
42 packets to ports 80 443 3000 3001 4000 4200 5000 5001 6443 7000 7001 8001 8181 8443 9000 9090 920 ...
show more
42 packets to ports 80 443 3000 3001 4000 4200 5000 5001 6443 7000 7001 8001 8181 8443 9000 9090 9200 9443
show less
Port Scan
๐จ๐ญ
pingusurmars
2026-05-19 00:23:52
(4 months ago)
Blocked by UFW on amperetwo [8888/tcp]
Source port: 50220
TTL: 252
Packet length: 40
TOS: 0x00
This ...
show more
Blocked by UFW on amperetwo [8888/tcp]
Source port: 50220
TTL: 252
Packet length: 40
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-05-18 23:32:44
(4 months ago)
unsolicited connect TCP dport 6443 (sport 47163)
Hacking
๐บ๐ธ
Choice Tech LLC
2026-05-18 23:25:24
(4 months ago)
Blocked by OPNsense firewall; 22 hits, proto=tcp, ports=3000,3001,4000,4200,443,5000,5001,6443,7000, ...
show more
Blocked by OPNsense firewall; 22 hits, proto=tcp, ports=3000,3001,4000,4200,443,5000,5001,6443,7000,7001,80,8000,800
show less
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-15 09:20:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:20:11.975202 2026] [security2:error] [pid 2614:tid 2614] [client 34.44.32.64:33820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.astroclima.verdadesreales.com"] [uri "/.git/config"] [unique_id "agblS3UHwXEnKzvEqMcaWAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-05-15 09:00:06
(4 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-05-15T08:47:29Z
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 YaBrowser/17.3.0.1785 Yowser/2.5 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-15 07:17:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:17:04.416770 2026] [security2:error] [pid 25945:tid 25945] [client 34.44.32.64:59526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hillconsultants.alhill.com"] [uri "/.git/config"] [unique_id "agbIcKf4BlRDduAOX1GHXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-05-15 06:45:14
(4 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-15 05:58:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 01:58:38.896751 2026] [security2:error] [pid 11874:tid 11874] [client 34.44.32.64:52008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mumawvickers.com"] [uri "/.git/config"] [unique_id "aga2DsoR7Er9CICRQIGkTgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 05:22:20
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 01:22:14.338809 2026] [security2:error] [pid 2000:tid 2000] [client 34.44.32.64:46488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "localpetsitters.com"] [uri "/.git/config"] [unique_id "agathvBC7Ai9J7hWW2vPxgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-15 04:32:20
(4 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2026-05-15 04:15:01
(4 months ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
octageeks.com
2026-05-15 04:08:19
(4 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 03:35:03
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.32.64 (64.32.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 23:34:58.461389 2026] [security2:error] [pid 15040:tid 15040] [client 34.44.32.64:35512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phalanxemail.net"] [uri "/.git/config"] [unique_id "agaUYudV6e3xIQpxrHI9mQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack