Anonymous
2026-09-07 05:18:57
(2 hours ago)
Blocked by firewall on hugin [2375/tcp] | Rule: UFW | SPT: 49168 | TTL: 56 | LEN: 60 | TOS: 0x00 • R ...
show more
Blocked by firewall on hugin [2375/tcp] | Rule: UFW | SPT: 49168 | TTL: 56 | LEN: 60 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇳🇱
Site.eu
2026-09-07 05:05:36
(2 hours ago)
Excessive multi-domain requests
Brute-Force
🇮🇹
paoloartone
2026-09-07 05:00:20
(2 hours ago)
Reverse proxy TCO: 493 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 06/09/202 ...
show more
Reverse proxy TCO: 493 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 06/09/2026.
show less
Web App Attack
Hacking
Port Scan
🇩🇪
BlueWire Hosting
2026-09-07 04:27:58
(3 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇳🇱
Savvii
2026-09-07 02:02:29
(5 hours ago)
20 attempts against mh_ha-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
noise.agency
2026-09-07 01:50:06
(5 hours ago)
35.236.164.45 (TW/Taiwan/45.164.236.35.bc.googleusercontent.com), more than 30 Apache 404 hits
Hacking
🇳🇱
homeshowdomain.nl
2026-09-06 21:59:54
(9 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-05.
show less
Web App Attack
SSH
Hacking
🇺🇸
agenciahypelab.com.br
2026-09-06 21:01:33
(10 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇳🇱
middelkoopcc
2026-09-06 20:14:01
(11 hours ago)
2026-09-06 22:07:07 GET /.git/config [404] && 2026-09-06 22:07:10 GET /.env [404] && 2026-09-06 22:0 ...
show more
2026-09-06 22:07:07 GET /.git/config [404] && 2026-09-06 22:07:10 GET /.env [404] && 2026-09-06 22:08:23 GET /app/.env [404] && 111 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:24:15
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.164.45 (45.164.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.164.45 (45.164.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:24:12.373144 2026] [security2:error] [pid 2735:tid 2735] [client 35.236.164.45:52234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.taekwondoit.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.taekwondoit.com"] [uri "/about-us/phpinfo.php.bak"] [unique_id "ap1bbCKSTkXdg6arB_rUlgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 06:38:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.164.45 (45.164.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.164.45 (45.164.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 02:38:38.820937 2026] [security2:error] [pid 24223:tid 24249] [client 35.236.164.45:43500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.royalbusinesscollege.com.aafm.us"] [uri "/.git/config"] [unique_id "ap0KbtGEdy9jKkGLr-MjrgAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 02:38:58
(1 day ago)
cloudlinux2 fail2ban: 2026-09-06 04:34:37,659 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-06 04:34:37,659 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.236.164.45 - 2026-09-06 04:34:37cloudlinux2 fail2ban: 2026-09-06 04:34:36,763 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.236.164.45 - 2026-09-06 04:34:36cloudlinux2 fail2ban: 2026-09-06 04:34:37,431 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.236.164.45 - 2026-09-06 04:34:37cloudlinux2 fail2ban: 2026-09-06 04:34:37,213 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.236.164.45 - 2026-09-06 04:34:37cloudlinux2 fail2ban: 2026-09-06 04:34:37,649 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Ban 35.236.164.45cloudlinux2 fail2ban: 2026-09-06 04:34:37,652 fail2ban.filter [1594]: INFO [recidive] Found 35.236.164.45 - 2026-09-06 04:34:37cloudlinux2 fail2ban: 2026-09-06 04:34:52,286 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.181.140.159cloudlinux2 fail2ban: 2026-09-06 04:34:58,738 fai
show less
Brute-Force
🇳🇱
homeshowdomain.nl
2026-09-05 22:01:40
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-05 20:58:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.164.45 (45.164.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.164.45 (45.164.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:58:44.463171 2026] [security2:error] [pid 4013:tid 4013] [client 35.236.164.45:40458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ronnycarrera.com.ctsaagt.org"] [uri "/.git/config"] [unique_id "apyChBaJsyFdXeGZoHCJrQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-05 19:10:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack