🇩🇪
jbcrn
2026-09-06 13:22:06
(7 hours ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /corset-preactivity. User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 05:55:54
(15 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
🇪🇸
el-brujo
2026-09-06 03:56:44
(17 hours ago)
06/Sep/2026:05:56:43.585088 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
06/Sep/2026:05:56:43.585088 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.116.88.6] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".resources"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "vlc.elhacker.net"] [uri "/vlc-winrt/2.7.0/VLC
...
show less
Hacking
Web App Attack
Anonymous
2026-09-06 02:53:50
(18 hours ago)
136.116.88.6 www.rolistore.com - [05/Sep/2026:14:38:46 -0600] "GET /?route=product/search&tag=argom ...
show more
136.116.88.6 www.rolistore.com - [05/Sep/2026:14:38:46 -0600] "GET /?route=product/search&tag=argom HTTP/1.1" 301 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36"
136.116.88.6 www.rolistore.com - [05/Sep/2026:14:38:47 -0600] "GET /?route=product/search&tag=argom HTTP/1.1" 200 624515 "http://www.rolistore.com/?route=product/search&tag=argom" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36"
136.116.88.6 www.rolistore.com - [05/Sep/2026:20:53:46 -0600] "GET /componentes-pc HTTP/1.1" 301 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
🇫🇷
Stylottica
2026-09-05 18:03:31
(1 day ago)
PrestaShop Security Module: nested/encoded redirect parameter abuse on "back" (occurrences=3)
Web App Attack
🇪🇸
el-brujo
2026-09-05 04:56:28
(1 day ago)
05/Sep/2026:06:56:28.080684 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
05/Sep/2026:06:56:28.080684 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.116.88.6] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".resources"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "vlc.elhacker.net"] [uri "/vlc-winrt/3.1.0/VLC
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:50:41
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.116.88.6 (6.88.116.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.116.88.6 (6.88.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:50:33.661929 2026] [security2:error] [pid 3660:tid 3660] [client 136.116.88.6:58866] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bkspeck.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bkspeck.com"] [uri "/bkspeck.com"] [unique_id "apsvGc45gNAsCGb1eC7KvwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-03 14:27:00
(3 days ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
🇸🇪
SkyDancer
2026-09-03 12:02:50
(3 days ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
Anonymous
2026-09-03 07:35:05
(3 days ago)
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probin ...
show more
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probing of administrative tools
show less
Brute-Force
Web App Attack
🇫🇷
Stylottica
2026-09-02 21:44:21
(3 days ago)
PrestaShop Security Module: nested/encoded redirect parameter abuse on "back" (occurrences=3)
Web App Attack
🇺🇸
webgobe
2026-09-02 20:29:13
(4 days ago)
wew-Joomla User : try to access forms...
Hacking
🇩🇪
jbcrn
2026-09-02 18:26:21
(4 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /leave. User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇳🇱
Cloud86 B.V.
2026-05-26 14:26:04
(3 months ago)
categories: Email Spam
Email Spam