ThreatBook.io
2025-03-16 00:36:52
(11 hours ago)
2025-03-15 08:47:44 /aab9
2025-03-15 08:47:39 /CTlY
2025-03-15 08:47:40 /yLES
2025 ... show more 2025-03-15 08:47:44 /aab9
2025-03-15 08:47:39 /CTlY
2025-03-15 08:47:40 /yLES
2025-03-15 08:47:42 /jquery-3.3.1.slim.min.js
2025-03-15 08:47:45 /jquery-3.3.2.slim.min.js
2025-03-15 08:47:41 /aab8 show less
Web App Attack
Starburst SysOp Team
2025-03-15 14:19:00
(22 hours ago)
[Sat Mar 15 14:19:19.064304 2025] [security2:error] [pid 425350:tid 425370] [client 148.153.56.86:47 ... show more [Sat Mar 15 14:19:19.064304 2025] [security2:error] [pid 425350:tid 425370] [client 148.153.56.86:47676] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/usr/local/apache/modsecurity-owasp-latest/coreruleset-4.11.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "711"] [id "920350"] [msg "Host header is a numeric IP address"] [data "188.68.43.240:443"] [severity "WARNING"] [ver "OWASP_CRS/4.11.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "188.68.43.240"] [uri "/3uAs"] [unique_id "Z9WMZ-OYNEYxog4dUSY0CAAAAM4"] show less
Hacking
Brute-Force
Web App Attack
Vieira Filho
2025-03-15 06:24:06
(1 day ago)
148.153.56.86 - - [15/Mar/2025:03:24:04 -0300] [35.198.31.82:80] "35.198.31.82" "GET /ADbu HTTP/1.1 ... show more 148.153.56.86 - - [15/Mar/2025:03:24:04 -0300] [35.198.31.82:80] "35.198.31.82" "GET /ADbu HTTP/1.1" 404 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 0.000
148.153.56.86 - - [15/Mar/2025:03:24:04 -0300] [35.198.31.82:80] "35.198.31.82" "GET /1rHr HTTP/1.1" 404 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 0.000
148.153.56.86 - - [15/Mar/2025:03:24:05 -0300] [35.198.31.82:80] "35.198.31.82" "GET /aab8 HTTP/1.1" 404 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 0.000
148.153.56.86 - - [15/Mar/2025:03:24:06 -0300] [35.198.31.82:80] "35.198.31.82" "GET /jquery-3.3.1.slim.min.js HTTP/1.1" 404 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 0.000
148.153.56.86 - - [15/Mar/2025:03:24:06 -0300] [35.198.31.82:80] "35.198.31.82" "GET /aab9 HTTP/1.1" 404 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:3
... show less
Brute-Force
Exploited Host
Web App Attack
WebTejo
2025-03-15 06:11:46
(1 day ago)
Detected multiple authentication failures and invalid user attempts from IP address 148.153.56.86 on ... show more Detected multiple authentication failures and invalid user attempts from IP address 148.153.56.86 on [PT] A01 Node show less
Brute-Force
SSH
SaltySoftworks
2025-03-15 05:27:43
(1 day ago)
Connecting to IP instead of domain name
Hacking
Web App Attack
xyz.rip
2025-03-15 01:59:34
(1 day ago)
WAF Violation...
Hacking
Web App Attack
GoodOldTOS
2025-03-14 05:49:46
(2 days ago)
Highly suspect IP
Hacking
Web App Attack
PlexLads
2025-03-13 08:35:43
(3 days ago)
148.153.56.86 - - [13/Mar/2025:01:35:40 -0700] "GET /4nMm HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Macint ... show more 148.153.56.86 - - [13/Mar/2025:01:35:40 -0700] "GET /4nMm HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [13/Mar/2025:01:35:40 -0700] "GET /cAIp HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [13/Mar/2025:01:35:40 -0700] "GET /aab8 HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [13/Mar/2025:01:35:40 -0700] "GET /jquery-3.3.1.slim.min.js HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [13/Mar/2025:01:35:40 -0700] "GET /aab9 HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [13/Mar/2025:01:35:40 -0700] "GET /jquery-3.3.2.slim.min.js HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko
... show less
Hacking
Web App Attack
Not Fake
2025-03-13 07:25:32
(3 days ago)
$f2bV_matches
Web App Attack
Honeypot-EU-Fru
2025-03-13 04:07:48
(3 days ago)
148.153.56.86 - - [redacted] [13/Mar/2025:05:07:46 +0100] "GET /r79z HTTP/1.1" 404 125 "-" "Mozilla/ ... show more 148.153.56.86 - - [redacted] [13/Mar/2025:05:07:46 +0100] "GET /r79z HTTP/1.1" 404 125 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 0.000 - -
148.153.56.8
... show less
Bad Web Bot
Web App Attack
aranguren.org
2025-03-13 03:12:14
(3 days ago)
148.153.56.86 - - [13/Mar/2025:14:12:08 +1100] "GET /O3eu HTTP/1.1" 404 1132 "https://203.132.94.196 ... show more 148.153.56.86 - - [13/Mar/2025:14:12:08 +1100] "GET /O3eu HTTP/1.1" 404 1132 "https://203.132.94.196:443/O3eu" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [13/Mar/2025:14:12:09 +1100] "GET /w1Sb HTTP/1.1" 404 1132 "https://203.132.94.196:443/w1Sb" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [13/Mar/2025:14:12:10 +1100] "GET /aab8 HTTP/1.1" 404 1132 "https://203.132.94.196:443/aab8" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [13/Mar/2025:14:12:11 +1100] "GET /jquery-3.3.1.slim.min.js HTTP/1.1" 404 1172 "https://203.132.94.196:443/jquery-3.3.1.slim.min.js" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [13/Mar/2025:14:12:12 +1100] "GET /aab9 HTTP/1.1" 404 1132 "https://203.132.94.196:443/aab9" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101
... show less
Bad Web Bot
diego
2025-03-12 03:41:04
(4 days ago)
[probe-68-69] 2025-03-12 03:41:04, Client: 148.153.56.86:48396, Protocol: 6, Unauthorized activity t ... show more [probe-68-69] 2025-03-12 03:41:04, Client: 148.153.56.86:48396, Protocol: 6, Unauthorized activity to HTTP: GET /BfDp show less
Web App Attack
PulseServers
2025-03-12 02:26:18
(4 days ago)
Probing a honeypot for vulnerabilities. Ignored robots.txt - CA10 Honeypot
...
Hacking
Web App Attack
Starburst SysOp Team
2025-03-12 01:45:00
(4 days ago)
[Wed Mar 12 01:45:02.820634 2025] [security2:error] [pid 4011113:tid 4011158] [client 148.153.56.86: ... show more [Wed Mar 12 01:45:02.820634 2025] [security2:error] [pid 4011113:tid 4011158] [client 148.153.56.86:48064] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/usr/local/apache/modsecurity-owasp-latest/coreruleset-4.12.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "711"] [id "920350"] [msg "Host header is a numeric IP address"] [data "74.208.45.158:80"] [severity "WARNING"] [ver "OWASP_CRS/4.12.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "74.208.45.158"] [uri "/lvI1"] [unique_id "Z9DnHpW7HofxCHOgDhoHkQAAAM8"] show less
Hacking
Brute-Force
Web App Attack
aranguren.org
2025-03-11 03:04:38
(5 days ago)
148.153.56.86 - - [11/Mar/2025:14:04:36 +1100] "GET /tn2H HTTP/1.1" 404 986 "-" "Mozilla/5.0 (Macint ... show more 148.153.56.86 - - [11/Mar/2025:14:04:36 +1100] "GET /tn2H HTTP/1.1" 404 986 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [11/Mar/2025:14:04:36 +1100] "GET /Tt4a HTTP/1.1" 404 986 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [11/Mar/2025:14:04:36 +1100] "GET /aab8 HTTP/1.1" 404 986 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [11/Mar/2025:14:04:37 +1100] "GET /jquery-3.3.1.slim.min.js HTTP/1.1" 404 986 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [11/Mar/2025:14:04:37 +1100] "GET /aab9 HTTP/1.1" 404 986 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.86 - - [11/Mar/2025:14:04:37 +1100] "GET /jquery-3.3.2.slim.min.js HTTP/1.1" 404 986 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko
... show less
Bad Web Bot