๐ฉ๐ช
jbcrn
2026-10-10 16:24:07
(6 hours ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /fediverse/post/deflagration.pawl/slanderful/Nautilacea/coprolagnist/dynamometamorphism-punctule/Gargantuan/. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-10-10 02:25:44
(20 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 72>=65, Abuse 75, NonEU, first-seen, Change* path)
show less
Hacking
Exploited Host
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-09 13:35:13
(1 day ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
Anonymous
2026-10-08 16:31:16
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
๐จ๐ฟ
Countryman
2026-09-30 00:10:01
(1 week ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐บ๐ธ
micropedro
2026-09-29 23:18:07
(1 week ago)
4 incidents: malicious activity. First: 2026-09-22 20:16, Last: 2026-09-29 19:18 UTC. Triggers: unkn ...
show more
4 incidents: malicious activity. First: 2026-09-22 20:16, Last: 2026-09-29 19:18 UTC. Triggers: unknown.
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-29 20:34:50
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:34:45.075780 2026] [security2:error] [pid 31106:tid 31106] [client 103.190.35.146:56503] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "schlegelcreative.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "arwg5TlElUShCJNPJUYOPwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 06:26:01
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 02:25:57.988949 2026] [security2:error] [pid 15576:tid 15576] [client 103.190.35.146:42006] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||panierduvillage.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "panierduvillage.com"] [uri "/"] [unique_id "artZ9bp1ht1It5ycz6LxNAAAAAU"], referer: https://thepanier.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-28 01:51:46
(1 week ago)
Shop search flood (L7 DDoS) | path: /2-accueil | query: q=Famille-Terra+Race-XRM-Domingo | src_port: ...
show more
Shop search flood (L7 DDoS) | path: /2-accueil | query: q=Famille-Terra+Race-XRM-Domingo | src_port: 38634 | 2026-09-28 01:51 UTC
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 08:14:36
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 04:14:28.118811 2026] [security2:error] [pid 27433:tid 27433] [client 103.190.35.146:33424] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||thebeeplace.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "thebeeplace.com"] [uri "/classes"] [unique_id "ard-5PGZucpkqIv_sMP5ywAAAAo"], referer: https://thebeesgold.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 02:25:34
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 22:25:20.056618 2026] [security2:error] [pid 20560:tid 20560] [client 103.190.35.146:51647] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||glolady.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "glolady.com"] [uri "/dev/admin.sql"] [unique_id "arctELcV17AWMymLCtUmxgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 09:12:56
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 103.190.35.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 05:12:50.308434 2026] [security2:error] [pid 1358:tid 1358] [client 103.190.35.146:36172] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||spirits66.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "spirits66.com"] [uri "/"] [unique_id "arOYEt9cQ9TiOT1evDX82wAAABU"], referer: https://route66news.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
bmino.pl
2026-09-23 06:03:00
(2 weeks ago)
Autoban IP(2): 103.190.35.146 - Hostname: Penta Online - City: Khulna - Country: Bangladesh - Organi ...
show more
Autoban IP(2): 103.190.35.146 - Hostname: Penta Online - City: Khulna - Country: Bangladesh - Organization: Md. Sanaulla/Md Sanaulla - Reason: GET /?q=xxcw167lew46329gqhdpuza HTTP/1.1
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 05:00:36
(2 weeks ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /sitemap.xml | 2026-09-21 05:00 UTC
show less
Bad Web Bot
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-20 16:21:33
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Bad Web Bot