Detected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt ...
show moreDetected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt.vn). The bot attempts to access non-existent files with the '.bs_model' extension appended to valid WordPress URLs (e.g., /tag/xyz/.bs_model). This indicates a coordinated search for specific vulnerabilities, BetterStudio exploits, or previously planted backdoors
show less
[Thu Nov 27 02:28:53.997490 2025] [security2:error] [pid 195094:tid 139900070377152] [client 14.191. ...
show more[Thu Nov 27 02:28:53.997490 2025] [security2:error] [pid 195094:tid 139900070377152] [client 14.191.208.63:15875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Brave" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "252"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Brave found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Brave Chrome/87.0.4280.67 Safari/537.36 request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/indeks-kekeringan-dan-kebasahan-meteorologis-3-bulanan-di-provinsi-jawa-timur/555562563-prediksi-bulanan-indeks-kekeringan-dan-kebasahan-meteorologis-3-bulanan-di-provinsi-jawa-timur-untuk-bulan-oktober-november-desember-tahun-2025-update-dari-analisis-bulan-..."] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/i
...
show less
Hacking
Web App Attack
Anonymous
scanning http requests from known botnet
Web App Attack
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
IP: 14.191.208.63
Protocol: TCP
Source port: 22691
Destination port: 1433
TTL: 235
Packet length: 40 ...
show moreIP: 14.191.208.63
Protocol: TCP
Source port: 22691
Destination port: 1433
TTL: 235
Packet length: 40
TOS: 0x00
Timestamp: Aug 8 05:28:24 (05:28:24, 08.08.2024)
The IP address was blocked by the Uncomplicated Firewall (UFW) due to suspicious activity. Packet details suggest a possible unauthorized access or port scanning attempt.
show less
Port Scan
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ