Anonymous
2026-06-18 02:49:59
(10 hours ago)
Aggressive web scan
Web App Attack
๐ท๐ด
SpamStopper
2026-06-18 02:24:38
(10 hours ago)
Automated mitigation by Fail2Ban firewall due to persistent security policy violations.
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
drewf.ink
2026-06-18 01:07:33
(11 hours ago)
[01:07] Port scanning. Port(s) scanned: TCP/2086, TCP/2087
Port Scan
๐ฉ๐ช
andrepcg
2026-06-18 00:54:15
(12 hours ago)
Port scanning (52.173.108.17 -> :2087)
Port Scan
Brute-Force
๐ท๐ธ
Scan
2026-06-18 00:43:37
(12 hours ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
๐บ๐ธ
xmission.com
2026-06-13 10:14:14
(5 days ago)
Blocked by UFW (TCP on 2087)
Source port: 54337
TTL: 51
Packet length: 60
TOS: 0x00
This report (fo ...
show more
Blocked by UFW (TCP on 2087)
Source port: 54337
TTL: 51
Packet length: 60
TOS: 0x00
This report (for 52.173.108.17) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
RAP
2026-06-13 08:59:25
(5 days ago)
2026-06-13 08:59:25 UTC Unauthorized activity to TCP port 8443. Web App
Port Scan
Web App Attack
๐บ๐ธ
Moby
2026-06-13 06:45:52
(5 days ago)
52.173.108.17 - - [13/Jun/2026:01:45:47 -0500] "GET /.git/HEAD HTTP/1.1" 404 984 "-" "Mozilla/5.0 (X ...
show more
52.173.108.17 - - [13/Jun/2026:01:45:47 -0500] "GET /.git/HEAD HTTP/1.1" 404 984 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0" "75.88.18.221" "75.88.18.221"
52.173.108.17 - - [13/Jun/2026:01:45:49 -0500] "GET /.git/config HTTP/1.1" 404 984 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "75.88.18.221" "75.88.18.221"
52.173.108.17 - - [13/Jun/2026:01:45:51 -0500] "GET /.env.local HTTP/1.1" 404 984 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0" "75.88.18.221" "75.88.18.221"
...
show less
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-06-13 05:20:31
(5 days ago)
2026-06-13T08:20:31.066983+03:00 6kw kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:16:3e:b6:e7:09:78:9a:18 ...
show more
2026-06-13T08:20:31.066983+03:00 6kw kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:16:3e:b6:e7:09:78:9a:18:bd:57:7e:08:00 SRC=52.173.108.17 DST=5.61.88.83 LEN=60 TOS=0x00 PREC=0x00 TTL=44 ID=59083 DF PROTO=TCP SPT=54442 DPT=2086 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ซ๐ท
dynamix
2026-06-13 04:46:03
(5 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
xmission.com
2026-06-09 17:23:42
(1 week ago)
Blocked by UFW (TCP on 2087)
Source port: 51338
TTL: 51
Packet length: 60
TOS: 0x00
This report (fo ...
show more
Blocked by UFW (TCP on 2087)
Source port: 51338
TTL: 51
Packet length: 60
TOS: 0x00
This report (for 52.173.108.17) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-09 16:44:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 52.173.108.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 52.173.108.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:44:43.525839 2026] [security2:error] [pid 28523:tid 28523] [client 52.173.108.17:51869] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.175"] [uri "/.git/HEAD"] [unique_id "aihC-xl2abUJ5nBTItW1NgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
RatCommander
2026-06-09 16:12:11
(1 week ago)
CrowdSec: crowdsecurity/http-probing
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 07:06:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 52.173.108.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 52.173.108.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 03:06:37.140252 2026] [security2:error] [pid 1198:tid 1198] [client 52.173.108.17:35662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.61"] [uri "/.git/HEAD"] [unique_id "aiZp_chA2aeHDtTQ0y5N3wAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-08 06:42:34
(1 week ago)
Multiple WAF Violations
Web App Attack