๐จ๐ญ
Origon
2026-07-27 16:38:45
(1 day ago)
postfix-non-smtp-command - IP: 52.125.136.4 - time="2026-07-27T18:38:45+02:00" level=info msg="(555 ...
show more
postfix-non-smtp-command - IP: 52.125.136.4 - time="2026-07-27T18:38:45+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/postfix-non-smtp-command by ip 52.125.136.4 (US/8075) : 4h ban on Ip 52.125.136.4" module=db
show less
Email Spam
๐บ๐ธ
TPI-Abuse
2026-07-24 20:22:24
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 16:22:17.032736 2026] [security2:error] [pid 831639:tid 831639] [client 52.125.136.4:3138] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.schryverdesign.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.schryverdesign.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "amPJed9vdcSrVYXpMChZ4gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 10:49:35
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:49:29.131118 2026] [security2:error] [pid 1378332:tid 1378332] [client 52.125.136.4:1093] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.haciendaefrain.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.haciendaefrain.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "amNDOSMYICKsSTNo1a1pOQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-07-21 14:21:08
(1 week ago)
tcp/443 (44 or more attempts)
Port Scan
๐บ๐ธ
MPL
2026-07-15 23:30:19
(1 week ago)
tcp/443 (20 or more attempts)
Port Scan
๐บ๐ธ
oukat
2026-07-09 04:34:45
(2 weeks ago)
POP3/IMAP/SMTP-submission authentication brute-force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-06 19:03:19
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 15:03:13.477361 2026] [security2:error] [pid 20674:tid 20674] [client 52.125.136.4:9291] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.impgs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.impgs.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akv78aOMguPnVKqiip86FAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
sonot
2026-07-04 20:48:39
(3 weeks ago)
Blocked by UFW on mail [80/tcp] | SPT: 3136 | TTL: 41 | LEN: 60 | TOS: 0x00 โข Reported by: github.co ...
show more
Blocked by UFW on mail [80/tcp] | SPT: 3136 | TTL: 41 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
masterguru
2026-06-29 12:57:57
(4 weeks ago)
*Port Scan* detected from 52.125.136.4 (US/United States/-). 11 hits in the last 105 seconds (0-164)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-24 16:27:43
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 12:27:38.810769 2026] [security2:error] [pid 8903:tid 8903] [client 52.125.136.4:11528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.kemela.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.kemela.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ajwFevJrlE-Egk--IaN5WgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 02:30:24
(1 month ago)
Port scanning blocked
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-18 18:23:32
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 14:23:27.400005 2026] [security2:error] [pid 30129:tid 30129] [client 52.125.136.4:11524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.grupo-visalud.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.grupo-visalud.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ajQ3n__Rxwc_Z3EgPMiwNgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 15:26:00
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:25:37.297031 2026] [security2:error] [pid 8548:tid 8571] [client 52.125.136.4:1344] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.urbanearthstudios.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.urbanearthstudios.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ajFq8SlTEfKruo62oyDYhgAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-06-04 02:20:06
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 00:18:49
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 52.125.136.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 20:18:28.710174 2026] [security2:error] [pid 15840:tid 15857] [client 52.125.136.4:7173] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.dwcwelding.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.dwcwelding.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ah9y1HyrPtKhnzdeqKMwHQAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack