πΊπΈ
xmission.com
2026-10-05 15:47:02
(1 day ago)
Blocked by UFW (TCP on 22)
Source port: 10618
TTL: 49
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 22)
Source port: 10618
TTL: 49
Packet length: 60
TOS: 0x00
This report (for 41.242.160.139) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
SSH
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-04 10:53:32
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 41.242.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 41.242.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 06:53:26.194042 2026] [security2:error] [pid 31154:tid 31154] [client 41.242.160.139:20094] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||nancyscafeandcatering.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nancyscafeandcatering.com"] [uri "/"] [unique_id "asIwJkC2Ap-k2zkHAwDR3QAAAAA"], referer: https://dabacklinks.website/dir/natural-link-building-services-144991
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
RAP
2026-10-04 04:30:02
(2 days ago)
2026-10-04 04:30:02 UTC Unauthorized activity to TCP port 22. SSH
SSH
π©πͺ
Vegascosmetics
2026-10-03 03:29:25
(3 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 77>=65, Abuse 85, NonEU, first-seen, Change* path)
show less
Hacking
Exploited Host
Web App Attack
π«π·
sthoyer.de
2026-10-01 19:09:03
(5 days ago)
Oct 1 21:09:01 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
Oct 1 21:09:01 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=41.242.160.139 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=50 ID=60390 DF PROTO=TCP SPT=9968 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
πΊπΈ
NetVexor
2026-10-01 08:11:21
(5 days ago)
Attack source identified and submitted via NetVexor BGP Blackhole Network
Port Scan
Hacking
Brute-Force
Anonymous
2026-10-01 05:58:29
(5 days ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH
πΊπΈ
MPL
2026-10-01 04:26:12
(5 days ago)
tcp/22 (2 or more attempts)
Port Scan
πΉπ·
Domainhizmetleri.com
2026-09-30 10:37:10
(6 days ago)
Source: DH Hunter (Honeypot) | Reason: Portscan (1 ports, 1 attempts in 480h, non-TR)
Port Scan
πΊπΈ
bpolson
2026-09-30 03:21:03
(6 days ago)
WordPress Hacking/Scanning. (s1)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 07:29:59
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 41.242.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 41.242.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:29:52.564943 2026] [security2:error] [pid 29169:tid 29169] [client 41.242.160.139:19925] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bvnboysbasketball.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bvnboysbasketball.com"] [uri "/"] [unique_id "arto8EEoiqqOa0EjnDxAcAAAAAM"], referer: https://aibacklinkbuilder.online/dir/organic-growth-links-31538
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π·
noconex
2026-09-28 15:46:27
(1 week ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 41.242.160 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 41.242.160.139
show less
Port Scan
Brute-Force
SSH
π©πͺ
Admins@FBN
2026-09-28 04:43:31
(1 week ago)
FW-PortScan: Traffic Blocked srcport=9776 dstport=22
Port Scan
Hacking
SSH
π§π·
noconex
2026-09-27 14:02:08
(1 week ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 41.242.160 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 41.242.160.139
show less
Port Scan
Brute-Force
SSH
πΊπΈ
ne1for23
2026-09-25 15:30:23
(1 week ago)
Unauthorized access to SSH at 25/Sep/2026:15:30:22 +0000.
Port Scan
SSH