๐ช๐ธ
DXC-0
2026-08-25 03:00:24
(20 hours ago)
Multiple attacks on Honeypot servers
Web Spam
Brute-Force
Web App Attack
Hacking
๐ซ๐ฎ
6kilowatti
2026-08-22 10:54:39
(3 days ago)
2026-08-22T13:54:38.419216+03:00 koti kernel: [UFW BLOCK] IN=enp0s25 OUT= MAC=6c:62:6d:bd:29:2d:18:f ...
show more
2026-08-22T13:54:38.419216+03:00 koti kernel: [UFW BLOCK] IN=enp0s25 OUT= MAC=6c:62:6d:bd:29:2d:18:fd:74:70:71:9e:08:00 SRC=36.129.58.208 DST=10.0.0.30 LEN=60 TOS=0x00 PREC=0x00 TTL=231 ID=63204 DF PROTO=TCP SPT=56057 DPT=23 WINDOW=29200 RES=0x00 SYN URGP=0
...
show less
Port Scan
Anonymous
2026-08-19 16:45:06
(6 days ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Exploited Host
Bad Web Bot
๐บ๐ธ
RAP
2026-08-16 13:28:59
(1 week ago)
2026-08-16 13:28:59 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
๐บ๐ธ
RAP
2026-08-14 14:49:26
(1 week ago)
2026-08-14 14:49:26 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
๐บ๐ธ
xmission.com
2026-08-13 15:16:40
(1 week ago)
Blocked by UFW (TCP on 23)
Source port: 56060
TTL: 233
Packet length: 60
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 23)
Source port: 56060
TTL: 233
Packet length: 60
TOS: 0x08
This report (for 36.129.58.208) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
RAP
2026-08-07 02:57:22
(2 weeks ago)
2026-08-07 02:57:22 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
Anonymous
2026-07-29 17:28:25
(3 weeks ago)
denied SMB access attempt. destination port 445.
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-20 07:42:07
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 03:41:58.497433 2026] [security2:error] [pid 11215:tid 11215] [client 36.129.58.208:48501] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||sistemmail.net|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "sistemmail.net"] [uri "/"] [unique_id "al3RRqfjytmsJk_x1Ut94QAAAAM"], referer: http://sistemmail.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 21:29:08
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 17:29:03.647438 2026] [security2:error] [pid 19742:tid 19742] [client 36.129.58.208:25589] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||ageh.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "ageh.com"] [uri "/"] [unique_id "alQHH5XML2AJrGEchfQP3QAAAAA"], referer: https://ageh.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-06 00:29:02
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 20:28:54.675530 2026] [security2:error] [pid 15831:tid 15831] [client 36.129.58.208:22479] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||floorswedo.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "floorswedo.com"] [uri "/"] [unique_id "akr2xiaXog-QcA9V_hLA-wAAAA4"], referer: http://floorswedo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 18:53:51
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 14:53:46.132370 2026] [security2:error] [pid 6209:tid 6209] [client 36.129.58.208:28035] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.hotpay.co|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.hotpay.co"] [uri "/"] [unique_id "akQQuhxqMIyYLAQ7igbLDwAAAAc"], referer: https://www.hotpay.co/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 18:54:04
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 14:53:57.882108 2026] [security2:error] [pid 20923:tid 20923] [client 36.129.58.208:0] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:user-agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.ndanetworks.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.ndanetworks.com"] [uri "/"] [unique_id "akK_RZ0fmklfshFgygIsNwAAAA8"], referer: https://www.ndanetworks.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-25 06:29:17
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 02:29:13.816673 2025] [security2:error] [pid 3959:tid 3959] [client 36.129.58.208:49896] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.renju.net|F|4"] [data "close, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.renju.net"] [uri "/tournament/2415/game/99897/"] [unique_id "aNThOYA5rBBrCKubUMpNdwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 12:55:52
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 36.129.58.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 08:55:49.337015 2025] [security2:error] [pid 6680:tid 6680] [client 36.129.58.208:46055] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.renju.net|F|4"] [data "close, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.renju.net"] [uri "/game/116901"] [unique_id "aMF1VXZWP23gjPWrOQD5xwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack