π«π·
zulzeen
2026-06-18 16:55:16
(2 days ago)
[incypit-web] Banned by Fail2ban (Jail: syswarden-portscan)
Port Scan
π«π·
Catalin Negru
2026-06-18 13:23:02
(2 days ago)
2026-06-18 16:23:01,444 fail2ban.actions [2945670]: NOTICE [apache-security] Ban 52.242.243. ...
show more
2026-06-18 16:23:01,444 fail2ban.actions [2945670]: NOTICE [apache-security] Ban 52.242.243.104
2026-06-18 16:23:01,459 fail2ban.actions [2945670]: NOTICE [apache-scan] Ban 52.242.243.104
2026-06-18 16:23:01,491 fail2ban.actions [2945670]: NOTICE [apache-404] Ban 52.242.243.104
2026-06-18 16:23:01,536 fail2ban.actions [2945670]: NOTICE [web-scanner] Ban 52.242.243.104
2026-06-18 16:23:01,702 fail2ban.actions [2945670]: NOTICE [apache-dirscan] Ban 52.242.243.104
...
show less
Brute-Force
Web App Attack
π§π·
dominioz
2026-06-18 13:07:04
(2 days ago)
2026-06-18 13:06:49 GET /.git/HEAD - - 52.242.243.104 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+ ...
show more
2026-06-18 13:06:49 GET /.git/HEAD - - 52.242.243.104 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+14_4_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/124.0.0.0+Safari/537.36 - 404 1459
2026-06-18 13:06:51 GET /.git/config - - 52.242.243.104 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:125.0)+Gecko/20100101+Firefox/125.0 - 404 1459
2026-06-18 13:06:55 GET /.git/logs/HEAD - - 52.242.243.104 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+14.4;+rv:125.0)+Gecko/20100101+Firefox/125.0 - 404 1459
2026-06-18 13:06:57 GET /.git/refs/heads/main - - 52.242.243.104 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:125.0)+Gecko/20100101+Firefox/125.0 - 404 1459
...
show less
Web App Attack
πΊπΈ
xmission.com
2026-06-18 12:47:31
(2 days ago)
Blocked by UFW (TCP on 2078)
Source port: 57600
TTL: 51
Packet length: 60
TOS: 0x00
This report (fo ...
show more
Blocked by UFW (TCP on 2078)
Source port: 57600
TTL: 51
Packet length: 60
TOS: 0x00
This report (for 52.242.243.104) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π©πͺ
maxpower
2026-06-18 12:16:19
(2 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 52.242.243.104 (US/United States/-): 2 i ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 52.242.243.104 (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 52.242.243.104 - - [18/Jun/2026:14:16:16 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" "-" host=51.89.2.98
52.242.243.104 - - [18/Jun/2026:14:16:18 +0200] "GET /.aws/credentials HTTP/1.1" 404 10387 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "-" host=51.89.2.98
show less
Port Scan
π§π·
chronos
2026-06-18 11:42:05
(2 days ago)
Web traffic. Possible probing or exploitation attempts. | Port: 80 | Proto: TCP | Location: United S ...
show more
Web traffic. Possible probing or exploitation attempts. | Port: 80 | Proto: TCP | Location: United States, Des Moines
show less
Bad Web Bot
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2026-06-18 11:33:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.242.243.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.242.243.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 07:33:54.440843 2026] [security2:error] [pid 22486:tid 22502] [client 52.242.243.104:57979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.134"] [uri "/.git/HEAD"] [unique_id "ajPXooBnFFrKzH_kOjLR-QAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-04-27 19:11:34
(1 month ago)
Blocked by UFW (TCP on 9050)
Source port: 21504
TTL: 241
Packet length: 40
TOS: 0x00
This report (f ...
show more
Blocked by UFW (TCP on 9050)
Source port: 21504
TTL: 241
Packet length: 40
TOS: 0x00
This report (for 52.242.243.104) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-04-27 18:42:09
(1 month ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
πΊπΈ
Rayulcifer
2026-04-06 18:03:27
(2 months ago)
52.242.243.104 - - [06/Apr/2026:13:03:13 -0500] "CONNECT graph.vshield.pro:443 HTTP/1.1" 502 488 "-" ...
show more
52.242.243.104 - - [06/Apr/2026:13:03:13 -0500] "CONNECT graph.vshield.pro:443 HTTP/1.1" 502 488 "-" "-"
52.242.243.104 - - [06/Apr/2026:13:03:13 -0500] "\x16\x03\x01" 400 392 "-" "-"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH