๐ธ๐ช
OnTheEdge
2026-08-23 13:58:52
(12 hours ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ช๐ธ
librebit
2026-08-23 12:42:53
(13 hours ago)
Brute force
Brute-Force
๐ฉ๐ช
dispaisyenterprises
2026-08-21 18:07:32
(2 days ago)
Honeypot [fra-de-honeypot]: Incoming HTTP traffic on port 81
Reported by DisPaisy Enterprises (dispa ...
show more
Honeypot [fra-de-honeypot]: Incoming HTTP traffic on port 81
Reported by DisPaisy Enterprises (dispaisy.systems) using: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Hacking
Bad Web Bot
๐ฎ๐ฑ
spd.co.il
2026-05-20 10:03:24
(3 months ago)
Web application attack detected
Hacking
Web App Attack
๐บ๐ธ
MPL
2026-04-04 12:36:35
(4 months ago)
tcp/80 (4 or more attempts)
Port Scan
๐ง๐ช
sid3windr
2026-03-27 23:07:56
(4 months ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-03-16 02:31:12
(5 months ago)
89.37.63.238 - - [16/Mar/2026:04:31:12 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows ...
show more
89.37.63.238 - - [16/Mar/2026:04:31:12 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
Anonymous
2026-03-03 18:25:35
(5 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-02-27 18:42:56
(5 months ago)
(mod_security) mod_security (id:220150) triggered by 89.37.63.238 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:220150) triggered by 89.37.63.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 13:42:50.362647 2026] [security2:error] [pid 28872:tid 29012] [client 89.37.63.238:21777] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:ID. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||www.seips.org|F|2"] [data "554/**//**/and/**/row(2018,1386)>(select/**/count(*),concat(0x39756434,(select/**/(elt(2836=2836,1))),0x57415748,floor(rand(0)*2))x/**/from/**/(select/**/2027/**/union/**/select/**/8505/**/union/**/select/**/7491/**/union/**/select/**/4808)a/**/group/**/by/**/x)#"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.seips.org"] [uri "/viewitem.php"] [unique_id "aaHlqqByaygIGrblKsrb9wAAAkY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-21 10:03:02
(6 months ago)
"Malicius Bot Scanner"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 20:59:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 89.37.63.238 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.37.63.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 15:59:39.003020 2026] [security2:error] [pid 26228:tid 26228] [client 89.37.63.238:54420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.159"] [uri "/.env"] [unique_id "aZYoO7Mj4vcn7zXMfyB7igAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-02-10 11:12:48
(6 months ago)
Blocked by UFW (TCP on 51728)
Source port: 48658
TTL: 44
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 51728)
Source port: 48658
TTL: 44
Packet length: 60
TOS: 0x08
This report (for 89.37.63.238) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-02-08 08:08:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 89.37.63.238 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.37.63.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 03:08:16.980031 2026] [security2:error] [pid 8833:tid 8833] [client 89.37.63.238:44566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.243"] [uri "/.env"] [unique_id "aYhEcJuRPebR70Ll2YiwFwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-02-06 18:17:48
(6 months ago)
Blocked by UFW (TCP on 51728)
Source port: 50796
TTL: 45
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 51728)
Source port: 50796
TTL: 45
Packet length: 60
TOS: 0x08
This report (for 89.37.63.238) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
technojoe99
2026-02-04 05:05:01
(6 months ago)
Exploit scan from 89.37.63.238. GET /.env HTTP/1.1.
Web App Attack