Anonymous
2026-07-01 16:45:10
(9 hours ago)
Web App Attack
Web App Attack
๐ท๐ธ
Scan
2026-06-03 00:12:36
(4 weeks ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
๐ฆ๐น
urnilxfgbez
2026-06-02 22:45:00
(4 weeks ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-02 21:59:41
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 17:59:37.316271 2026] [security2:error] [pid 28785:tid 28785] [client 4.246.135.165:3585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.20"] [uri "/wp-config.php"] [unique_id "ah9SSXAuDjWlQY0LSnDRAwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Ribeye375
2026-06-02 21:53:49
(4 weeks ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 20:57:40
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 16:57:33.066801 2026] [security2:error] [pid 11823:tid 11823] [client 4.246.135.165:3278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.121"] [uri "/.env"] [unique_id "ah9DvXJFiLP_v_t5lRGoPwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
centurion
2026-06-02 20:46:33
(4 weeks ago)
Blocked by UFW on dc00 [80/tcp]
Source port: 3878
TTL: 48
Packet length: 60
TOS: 0x00
This report w ...
show more
Blocked by UFW on dc00 [80/tcp]
Source port: 3878
TTL: 48
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
xmission.com
2026-06-02 19:51:36
(4 weeks ago)
Blocked by UFW (TCP on 8443)
Source port: 4012
TTL: 48
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 8443)
Source port: 4012
TTL: 48
Packet length: 60
TOS: 0x00
This report (for 4.246.135.165) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฌ๐ง
PeravixGroup
2026-06-02 19:06:18
(4 weeks ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
Anonymous
2026-06-02 18:35:42
(4 weeks ago)
4.246.135.165 - - [02/Jun/2026:20:35:42 +0200] "GET /.git/config HTTP/1.1" 402 829 "-" "Mozilla/5.0 ...
show more
4.246.135.165 - - [02/Jun/2026:20:35:42 +0200] "GET /.git/config HTTP/1.1" 402 829 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0" ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:54:24
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:54:18.542852 2026] [security2:error] [pid 2112:tid 2112] [client 4.246.135.165:3356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.206"] [uri "/.git/HEAD"] [unique_id "ah8Yyt2lWls0My7GY1wkKQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:20:51
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:20:44.541639 2026] [security2:error] [pid 20503:tid 20503] [client 4.246.135.165:3632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.38"] [uri "/.git/HEAD"] [unique_id "ah8Q7Aa4RLQcz9EH7sbjEQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:02:00
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 4.246.135.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:01:56.810635 2026] [security2:error] [pid 11814:tid 11814] [client 4.246.135.165:3338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.16"] [uri "/.git/HEAD"] [unique_id "ah8MhGgfQFYY3xpFby9jiQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 16:58:52
(4 weeks ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
Rayulcifer
2026-04-24 11:10:50
(2 months ago)
4.246.135.165 - - [24/Apr/2026:06:10:50 -0500] "GET http://clients2.google.com/time/1/current?cup2ke ...
show more
4.246.135.165 - - [24/Apr/2026:06:10:50 -0500] "GET http://clients2.google.com/time/1/current?cup2key=9:iwtucK9FCuELqKZ9Ga8XBPu0W0y7xnWm4cbTJI49IbM&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 HTTP/1.1" 200 855 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
4.246.135.165 - - [24/Apr/2026:06:10:50 -0500] "CONNECT www.google.com:443 HTTP/1.1" 502 488 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH