๐จ๐ฟ
lp
2026-01-20 07:24:26
(4 months ago)
Email account brute force: 6 attempts were recorded from 37.19.198.83
2026-01-20T07:28:52+01:00 warn ...
show more
Email account brute force: 6 attempts were recorded from 37.19.198.83
2026-01-20T07:28:52+01:00 warning: unknown[37.19.198.83]: SASL PLAIN authentication failed: authentication failure, [email protected]
2026-01-20T07:28:52+01:00 warning: unknown[37.19.198.83]: SASL LOGIN authentication failed: authentication failure, [email protected]
2026-01-20T07:28:53+01:00 warning: unknown[37.19.198.83]: SASL PLAIN authentication failed: authentication failure, [email protected]
2026-01-20T07:28:53+01:00 warning: unknown[37.19.198.83]: SASL LOGIN authentication failed: authentication failure, [email protected]
2026-01-20T07:29:01+01:00 warning: unknown[37.19.198.83]: SASL PLAIN authentication failed: authentication failure, [email protected]
2026-01-20T07:29:01+01:00 warning: unknown[37.19.198.83]: SASL LOGIN authentication failed: aut
show less
Brute-Force
๐บ๐ธ
xmission.com
2025-12-18 20:10:08
(5 months ago)
Blocked by UFW (TCP on 55756)
Source port: 52925
TTL: 51
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 55756)
Source port: 52925
TTL: 51
Packet length: 60
TOS: 0x08
This report (for 37.19.198.83) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
marzzzello
2025-12-11 01:02:17
(6 months ago)
Ports: 25x 26709
Port Scan
Anonymous
2025-09-18 17:20:12
(8 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
๐บ๐ธ
TPI-Abuse
2025-09-07 09:59:50
(9 months ago)
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (unn-37-19-198-83.datapacket.com): ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (unn-37-19-198-83.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 05:59:45.087965 2025] [security2:error] [pid 22098:tid 22098] [client 37.19.198.83:49972] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.leesart.net|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.leesart.net"] [uri "/robots.txt"] [unique_id "aL1XkXgs6xFvqhYUjVIVmAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 20:12:15
(9 months ago)
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (unn-37-19-198-83.datapacket.com): ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (unn-37-19-198-83.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 16:12:11.441106 2025] [security2:error] [pid 1834:tid 1834] [client 37.19.198.83:43314] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.valentinemoore.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.valentinemoore.com"] [uri "/robots.txt"] [unique_id "aLyVm8mEclOEq-AvBThPOwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2025-09-05 07:15:32
(9 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2025-09-05 04:08:26
(9 months ago)
Excessive crawling/scraping
Hacking
Brute-Force
Anonymous
2025-09-04 08:15:15
(9 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
Anonymous
2025-09-01 08:10:14
(9 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
๐บ๐ธ
TPI-Abuse
2025-08-30 23:44:16
(9 months ago)
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (unn-37-19-198-83.datapacket.com): ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (unn-37-19-198-83.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 30 19:44:10.393229 2025] [security2:error] [pid 7259:tid 7259] [client 37.19.198.83:54032] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.acadianahero.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.acadianahero.com"] [uri "/robots.txt"] [unique_id "aLOMylXYyirBEOPLjm7WAgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-08-30 14:30:18
(9 months ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ฉ๐ช
LRob.fr
2025-08-30 09:15:38
(9 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-30 04:52:54
(9 months ago)
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (unn-37-19-198-83.datapacket.com): ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (unn-37-19-198-83.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 30 00:52:47.980296 2025] [security2:error] [pid 23796:tid 23796] [client 37.19.198.83:36504] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.soleillavie.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.soleillavie.com"] [uri "/robots.txt"] [unique_id "aLKDn6iRV0ljvi8nCYzhnwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2025-08-29 22:42:46
(9 months ago)
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (US/United States/unn-37-19-198-83 ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.198.83 (US/United States/unn-37-19-198-83.datapacket.com): 5 in the last 300 secs
show less
Email Spam
Brute-Force
Web App Attack