Abuse complaints

78.17.147.99:         2026-09-06 11:01.Categories: Port Scan.
Comment: SCAN: Host Sweep CloudCIX Reconnaissance Scan Detected, PTR: 464258.vm.spacecore.network.
        2026-09-05 11:01.Categories: Port Scan.
Comment: firewall-block, port(s): 4071/tcp
        2026-09-05 10:57.Categories: Port Scan.
Comment: Blocked by firewall on hugin [4080/tcp] | Rule: AbuseIPDB | SPT: 60001 | TTL: 245 | LEN: 40 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 10:38.Categories: Port Scan.
Comment: tcp/4082 (6 or more attempts)
        2026-09-05 10:37.Categories: Port Scan.
Comment: trying to access non-authorized port
        2026-09-05 10:37.Categories: Port Scan.
Comment: Blocked by on honeypot [4080/tcp] | SPT: 60001 | TTL: 244 | LEN: 40 | TOS: 0x00 • Reported by: abuse.terraforge.fun
        2026-09-05 10:25.Categories: Port Scan.
Comment: Blocked by UFW (TCP on 4072) Source port: 60001 TTL: 238 Packet length: 40 TOS: 0x08 This report (for 78.17.147.99) was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 10:08.Categories: DDoS Attack Participating, Port Scan.
Comment: fail2ban:firewall:2026-09-05T11:49:26.782605+02:00 <SRV> firewall: filter IN=<ANONYMIZED_INTERFACE> OUT= MAC=<ANONYMIZED_MAC> SRC=78.17.147.99 DST=<ANONYMIZED_IP> LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=43360 PROTO=TCP SPT=60001 DPT=4085 WINDOW=1024 RES=0x00 SYN URGP=0 2026-09-05T12:08:48.886344+02:00 <SRV> firewall: filter IN=<ANONYMIZED_INTERFACE> OUT= MAC=<ANONYMIZED_MAC> SRC=78.17.147.99 DST=<PRIVATE_IPv4> LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=33325 PROTO=TCP SPT=60001 DPT=4075 WINDOW=1024 RES=0x00 SYN URGP=0
        2026-09-05 10:08.Categories: Port Scan.
Comment: Blocked by UFW on celestialcityna [4082/tcp] | SPT: 60001 | TTL: 235 | LEN: 40 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 10:05.Categories: Port Scan, Hacking, Exploited Host.
Comment: Port probing on unauthorized port 4076
        2026-09-05 09:51.Categories: Port Scan.
Comment: Blocked by UFW on pbcd1 [4084/tcp] | SPT: 60001 | TTL: 238 | LEN: 40 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 09:51.Categories: Port Scan.
Comment: Drop from IP address 78.17.147.99 to tcp-port 4077
        2026-09-05 09:46.Categories: Port Scan.
Comment: 🛡️ Honeypot [bsts-tpot-hive]: Empty payload (likely service probe); 4083 [1] TCP
        2026-09-05 09:41.Categories: Brute-Force, SSH.
Comment: DShield firewall scan – TCP to port 4079
        2026-09-05 09:34.Categories: Port Scan.
Comment: Blocked by UFW (TCP on 4082) Source port: 60001 TTL: 238 Packet length: 40 TOS: 0x08 This report (for 78.17.147.99) was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 09:30.Categories: Port Scan, Brute-Force.
Comment: NFT blocked 78.17.147.99 on 05-Sep-2026..
        2026-09-05 09:27.Categories: Port Scan.
Comment: FW-PortScan: Traffic Blocked srcport=60001 dstport=4083
        2026-09-05 09:22.Categories: Port Scan.
Comment: 2026-09-05T12:22:54.736461+03:00 oh6ah kernel: [UFW BLOCK] IN=enp2s0 OUT= MAC=00:26:18:a8:d6:75:2e:2d:5e:71:aa:73:08:00 SRC=78.17.147.99 DST=192.168.0.102 LEN=44 TOS=0x18 PREC=0x20 TTL=241 ID=62988 PROTO=TCP SPT=60001 DPT=4080 WINDOW=1024 RES=0x00 SYN URGP=0 …
        2026-09-05 09:22.Categories: Port Scan.
Comment: tcp/4080
        2026-09-05 09:09.Categories: Port Scan.
Comment: Honeypot hit: Empty payload (likely service probe); 4082 [1] TCP
        2026-09-05 08:59.Categories: Port Scan.
Comment: Probed 1 time(s): TCP/4083
        2026-09-05 08:56.Categories: Port Scan.
Comment: Port scan detected on port 4082 (connection without data transfer)
        2026-09-05 08:51.Categories: Port Scan.
Comment: [2026-09-05T08:51:35Z] Unsolicited scan from 78.17.147.99 to port 4078/tcp
        2026-09-05 08:43.Categories: Port Scan.
Comment: Port scan from this IP. Firewall dropped every packet. Targeted TCP ports: 4079, 4082. Activity window: 2026-09-05 07:41 UTC to 2026-09-05 08:43 UTC.
        2026-09-05 08:43.Categories: Port Scan.
Comment: Blocked by UFW (TCP on 4074) Source port: 60001 TTL: 238 Packet length: 40 TOS: 0x08 This report (for 78.17.147.99) was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 08:37.Categories: Port Scan.
Comment: 2026-09-05T11:37:34.869046+03:00 mummo kernel: [UFW BLOCK] IN=enp0s25 OUT= MAC=6c:62:6d:d6:a5:bc:00:00:5e:00:01:58:08:00 SRC=78.17.147.99 DST=83.148.240.21 LEN=40 TOS=0x00 PREC=0x00 TTL=244 ID=10814 PROTO=TCP SPT=60001 DPT=4081 WINDOW=1024 RES=0x00 SYN URGP=0 …
        2026-09-05 08:35.Categories: Email Spam, Port Scan.
Comment: connection to honeypot
        2026-09-05 08:32.Categories: Port Scan.
Comment: IPS Detection: 78.17.147.99 -> DPT: 4083
        2026-09-05 08:29.Categories: Port Scan, Hacking.
Comment: Unsolicited TCP traffic on Honeypot, srcport=60001 dstport=4082
        2026-09-05 08:29.Categories: Port Scan.
Comment: Automated scan detection against redacted protected targets. Hits=1; port 4080 proto 6 detection dark_ip
        2026-09-05 08:29.Categories: Port Scan.
Comment: Network port/address scan: probed 1 distinct port(s) across 21 host(s); 100% of connections received no service (SYN, no reply) — passive network sensor.
        2026-09-05 08:27.Categories: Port Scan.
Comment: Port Scan …
        2026-09-05 08:26.Categories: Port Scan.
Comment: SP-Scan 60001:4081 detected 2026.09.05 10:26:29 blocked until 2026.10.25 02:29:16
        2026-09-05 08:21.Categories: Port Scan.
Comment: Unauthorized attempt on (TCP on port 4085). Source port: 60001 TTL: 246 Packet length: 40 Timestamp: 2026-09-05 10:20:59
        2026-09-05 08:16.Categories: Port Scan.
Comment: Blocked by UFW on NsmallFE [4075/tcp] | SPT: 60001 | TTL: 248 | LEN: 40 | TOS: 0x00
        2026-09-05 08:09.Categories: Port Scan.
Comment: [SRV-VPN1] Blocked by SysWarden Firewall (Port Scan / Probing)
        2026-09-05 08:07.Categories: Port Scan.
Comment: firewall port scanning detected. 2 or more observation(s) from 2026-09-05T08:07:27.000Z through 2026-09-05T08:07:27.000Z.
        2026-09-05 08:02.Categories: Port Scan.
Comment: Blocked by UFW on amperetwo [4080/tcp] Source port: 60001 TTL: 241 Packet length: 40 TOS: 0x00 This report was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 08:00.Categories: Port Scan.
Comment: Blocked by UFW (TCP on 4081) Source port: 60001 TTL: 238 Packet length: 40 TOS: 0x08 This report (for 78.17.147.99) was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 07:58.Categories: Port Scan.
Comment: UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=78.17.147.99; proto=TCP; source_port=60001; target_port=4080; flags=SYN
        2026-09-05 07:43.Categories: Port Scan.
Comment: Blocked by UFW (TCP on 4079) Source port: 60001 TTL: 237 Packet length: 40 TOS: 0x08 This report (for 78.17.147.99) was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter
        2026-09-05 07:40.Categories: Port Scan.
Comment: firewall-block, port(s): 4077/tcp
        2026-09-05 07:39.Categories: Hacking.
Comment: Repeated inbound connection attempts blocked by firewall. Observed at least twice within 24 hours.
        2026-09-05 07:33.Categories: Port Scan.
Comment: 2026-09-05T10:33:52.502972+03:00 6kw kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:16:3e:b6:e7:09:78:9a:18:bd:57:7e:08:00 SRC=78.17.147.99 DST=5.61.88.83 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=29049 PROTO=TCP SPT=60001 DPT=4077 WINDOW=1024 RES=0x00 SYN URGP=0 …
        2026-09-05 07:30.Categories: Port Scan.
Comment: Mass port scanning on a whole network
        2026-09-05 07:22.Categories: Port Scan, Brute-Force.
Comment: 2026-09-05T09:22:00.848295+02:00 vps kernel: [4963733.425513] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=78.17.147.99 DST=54.37.14.118 LEN=40 TOS=0x00 PREC=0x00 TTL=237 ID=54117 PROTO=TCP SPT=60001 DPT=4083 WINDOW=1024 RES=0x00 SYN URGP=0 …
        2026-09-05 07:19.Categories: Port Scan.
Comment: denied traffic to a non-approved destination port. destination port 4081.
        2026-09-05 07:18.Categories: Port Scan.
Comment: Blocked by UFW (TCP on 4080) Source port: 60001 TTL: 237 Packet length: 40 TOS: 0x08 This report (for 78.17.147.99) was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter