🇩🇪
SCHAPPY
2026-09-08 06:45:07
(7 hours ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
🇫🇷
Zundapper
2026-09-08 05:57:45
(8 hours ago)
68.183.89.143 - - [08/Sep/2026:07:56:51 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gra ...
show more
68.183.89.143 - - [08/Sep/2026:07:56:51 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:07:57:06 +0200] "GET /index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:07:57:07 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:07:57:28 +0200] "GET /?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari
...
show less
Web App Attack
Port Scan
🇩🇪
Dominik Lysiak
2026-09-08 05:33:12
(8 hours ago)
68.183.89.143 - - [08/Sep/2026:07:33:10 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gra ...
show more
68.183.89.143 - - [08/Sep/2026:07:33:10 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:07:33:10 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:07:33:12 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇨🇭
dalslab ltd
2026-09-08 04:55:46
(9 hours ago)
[08/Sep/2026:06:54:20 +0200] - 404 404 - GET https auth.dalslab.com "/wp-json/gravitysmtp/v1/tests/m ...
show more
[08/Sep/2026:06:54:20 +0200] - 404 404 - GET https auth.dalslab.com "/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings" [Client 68.183.89.143] [Length 5431] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-"
[08/Sep/2026:06:55:04 +0200] - 404 404 - GET https auth.dalslab.com "/index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings" [Client 68.183.89.143] [Length 5431] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-"
[08/Sep/2026:06:55:12 +0200] - 404 404 - GET https auth.dalslab.com "/wp-json/gravitysmtp/v1/tests/mock-data" [Client 68.183.89.143] [Length 5431] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-"
[08/Sep/2026:06:55:19 +0200] - 404 404 - GET http
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
David Ferneding
2026-09-08 04:48:43
(9 hours ago)
Blocked by UFW (TCP on 80)
Source port: 48972
TTL: 52
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 48972
TTL: 52
Packet length: 60
TOS: 0x00
This report (for 68.183.89.143) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
🇩🇪
findlab
2026-09-08 04:35:01
(9 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:33:33
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 68.183.89.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 68.183.89.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:33:27.853132 2026] [security2:error] [pid 1677:tid 1677] [client 68.183.89.143:53946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rockinr.brushmileage.org"] [uri "/wp-config.php.bak"] [unique_id "ap-QFwQ44KmEyzaLeLSrFwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-08 04:33:12
(9 hours ago)
Many_bad_calls
Web App Attack
🇺🇸
kosada.com
2026-09-08 02:29:20
(11 hours ago)
Repeated exploit attempts, for example: /en AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA ...
show more
Repeated exploit attempts, for example: /en AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA... (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 Chrome/122.0.0.0 Safari/537.36")
show less
Web App Attack
🇺🇸
mnsf
2026-09-08 02:05:16
(12 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 00:59:54
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 68.183.89.143 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 68.183.89.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:59:49.255254 2026] [security2:error] [pid 23838:tid 23838] [client 68.183.89.143:40658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "susanleeward.com"] [uri "/wp-config.php.bak"] [unique_id "ap9eBXYBQcedGY3_660bbQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 23:42:56
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
🇺🇸
TAY
2026-09-07 22:59:24
(15 hours ago)
68.183.89.143 - - [08/Sep/2026:06:55:26 +0800] "GET /wp-config.php.save HTTP/1.1" 404 48441 "-" "Moz ...
show more
68.183.89.143 - - [08/Sep/2026:06:55:26 +0800] "GET /wp-config.php.save HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:06:55:33 +0800] "GET /wp-config.php.old HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:06:55:34 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:06:55:35 +0800] "GET /wp-config.php.txt HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
68.183.89.143 - - [08/Sep/2026:06:55:37 +0800] "GET /wp-config.php.swp HTTP/1.1" 404 48441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTM
...
show less
Brute-Force
Anonymous
2026-09-07 22:33:10
(15 hours ago)
RUPLDE WEBEXPLOIT 68.183.89.143 (68.183.89.143)
Web App Attack
Anonymous
2026-09-07 21:15:03
(16 hours ago)
suspicious request in access.log
Web App Attack