🇩🇪
mxpgmbh
2026-09-06 10:44:43
(1 hour ago)
2026-09-06T12:44:09.184832+02:00 **** sshd-session[18358]: pam_unix(sshd:auth): authentication failu ...
show more
2026-09-06T12:44:09.184832+02:00 **** sshd-session[18358]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=149.102.130.252 user=root
2026-09-06T12:44:11.227004+02:00 **** sshd-session[18358]: Failed password for root from 149.102.130.252 port 53076 ssh2
2026-09-06T12:44:41.556592+02:00 **** sshd-session[18445]: Invalid user **** from 149.102.130.252 port 58716
2026-09-06T12:44:41.557685+02:00 **** sshd-session[18445]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=149.102.130.252
2026-09-06T12:44:43.106579+02:00 **** sshd-session[18445]: Failed password for invalid user **** from 149.102.130.252 port 58716 ssh2
show less
Brute-Force
SSH
🇮🇳
nadnitin
2026-09-06 10:43:53
(1 hour ago)
Automated trigger via Nginx Police. Reason: MALICIOUS-HEX. Trigger Log: 149.102.130.252 - - [06/Sep/ ...
show more
Automated trigger via Nginx Police. Reason: MALICIOUS-HEX. Trigger Log: 149.102.130.252 - - [06/Sep/2026:16:13:52 +0530] "POST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh HTTP/1.1" 400 166 "-" "-"
show less
Web App Attack
🇫🇮
Birdo
2026-09-06 10:36:53
(2 hours ago)
[Honeypot Report] Malware dropped following HTTP intrusion
An automated malware loader attempted to ...
show more
[Honeypot Report] Malware dropped following HTTP intrusion
An automated malware loader attempted to exploit CVE-2012-1823, then delivered an executable payload. Credentials and request paths match Apache HTTP Server (CGI), PHP-CGI.
Observed: 2026-09-06 10:36 UTC | 1 session | 93 events | HTTP (port 80)
Attack chain:
1. Exploit attempt: CVE-2012-1823 - PHP-CGI argument injection RCE [CISA KEV]
2. Exploit attempt: CVE-2021-41773 - Apache HTTP Server path traversal to RCE [CISA KEV]
3. Malicious script dropped: SHA-256 662a4c450a73dd45622856fb0f44cbbeab101a326b89aedbd07ec41c08a5f73b, 1,193 bytes, PHP source (likely webshell)
Technique: CWE-22 path traversal; CWE-98 remote file inclusion | Classification: malware loader | Signatures: PHPUnit eval-stdin.php RCE, PHP-CGI Argument Injection RCE
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/149.102.130.252.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
Exploited Host
Hacking
Web App Attack
🇩🇪
ut-addicted.com
2026-09-06 10:21:59
(2 hours ago)
\[Sun Sep 06 12:21:56.780904 2026\] \[:error\] \[pid 9983:tid 140352461670144\] \[client 149.102.130 ...
show more
\[Sun Sep 06 12:21:56.780904 2026\] \[:error\] \[pid 9983:tid 140352461670144\] \[client 149.102.130.252:40454\] \[client 149.102.130.252\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 28\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "78.46.187.162"\] \[uri "/hello.world"\] \[unique_id "ap0@xEr@AE9Wm7up2lcjcwAAANA"\]
show less
Brute-Force
Web App Attack
🇩🇪
fleckenbase
2026-09-06 10:13:47
(2 hours ago)
apache-noscript
...
Brute-Force
Web App Attack
🇹🇭
MWA SOC
2026-09-06 10:11:27
(2 hours ago)
Hacking
🇩🇪
maxpower
2026-09-06 10:05:24
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 149.102.130.252 (GB/United Kingdom/vmi18 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 149.102.130.252 (GB/United Kingdom/vmi1841141.contaboserver.net): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 149.102.130.252 - - [06/Sep/2026:12:05:20 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 200 11953 "-" "libredtail-http" "-" host=51.89.2.97
show less
Port Scan
🇫🇷
Thibault Millant
2026-09-06 10:04:00
(2 hours ago)
149.102.130.252 - - [06/Sep/2026:10:03:31 +0000] "GET /admin/vendor/phpunit/phpunit/src/Util/PHP/eva ...
show more
149.102.130.252 - - [06/Sep/2026:10:03:31 +0000] "GET /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 146 "-" "libredtail-http"
...
show less
Brute-Force
Exploited Host
SSH
Anonymous
2026-09-06 09:57:54
(2 hours ago)
[Sun Sep 06 11:57:53.817839 2026] [authz_core:error] [pid 19235] [client 149.102.130.252:47596] AH01 ...
show more
[Sun Sep 06 11:57:53.817839 2026] [authz_core:error] [pid 19235] [client 149.102.130.252:47596] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Sep 06 11:57:53.847720 2026] [authz_core:error] [pid 19235] [client 149.102.130.252:47596] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Sep 06 11:57:53.888376 2026] [authz_core:error] [pid 19235] [client 149.102.130.252:47596] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:38:40
(2 hours ago)
(mod_security) mod_security (id:218420) triggered by 149.102.130.252 (vmi1841141.contaboserver.net): ...
show more
(mod_security) mod_security (id:218420) triggered by 149.102.130.252 (vmi1841141.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:38:33.808255 2026] [security2:error] [pid 31765:tid 31765] [client 149.102.130.252:41100] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.5:443|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.5"] [uri "/hello.world"] [unique_id "ap00ma88VihIeN0fRxCrXgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
zulzeen
2026-09-06 09:28:19
(3 hours ago)
[incypit-web] Blocked by SysWarden Firewall [BLOCK] (Infra/DevOps Attack)
Hacking
Web App Attack
🇺🇸
MPL
2026-09-06 09:28:13
(3 hours ago)
tcp/443 (4 or more attempts)
Port Scan
🇵🇱
swiszczu
2026-09-06 09:24:54
(3 hours ago)
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
149.102.130.252 - - ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
149.102.130.252 - - [06/Sep/2026:11:24:53 +0200] "POST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 403 153 "-" "libredtail-http" "-"
149.102.130.252 - - [06/Sep/2026:11:24:53 +0200] "POST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 403 153 "-" "libredtail-http" "-"
149.102.130.252 - - [06/Sep/2026:11:24:53 +0200] "POST /index.php?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input HTTP/1.1" 403 153 "-" "libredtail-http" "-"
149.102.130.252 - - [06/Sep/2026:11:24:53 +0200] "POST /test.hello?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input HTTP/1.1" 403 153 "-" "libredtail-http" "-"
149.102.130.252 - - [06/Sep/2026:11:24:53 +0200] "POST /index.php?-d+a
show less
Hacking
Web App Attack
🇫🇷
mouafiq
2026-09-06 08:57:40
(3 hours ago)
2026-09-06 08:57:39,725 15486 INFO ? werkzeug: 149.102.130.252 - - [06/Sep/2026 08:57:39] "POST /hel ...
show more
2026-09-06 08:57:39,725 15486 INFO ? werkzeug: 149.102.130.252 - - [06/Sep/2026 08:57:39] "POST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.0" 404 - 1 0.002 0.007
2026-09-06 08:57:39,803 15486 INFO ? werkzeug: 149.102.130.252 - - [06/Sep/2026 08:57:39] "POST /index.php?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input HTTP/1.0" 404 - 1 0.002 0.004
2026-09-06 08:57:39,836 15395 INFO ? werkzeug: 149.102.130.252 - - [06/Sep/2026 08:57:39] "POST /test.hello?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input HTTP/1.0" 404 - 1 0.002 0.006
2026-09-06 08:57:39,870 15486 INFO ? werkzeug: 149.102.130.252 - - [06/Sep/2026 08:57:39] "POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp%3a//input HTTP/1.0" 404 - 1 0.002 0.005
2026-09-06 08:57:39,904 15395 INFO ? werkzeug: 149.102.130.252 - - [06/Sep/2026 08:57:39] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.0" 404 - 1 0.002 0.004
show less
Brute-Force
SSH
🇩🇪
mxpgmbh
2026-09-06 08:55:10
(3 hours ago)
2026-09-06T10:54:33.794501+02:00 **** sshd-session[2061]: pam_unix(sshd:auth): authentication failur ...
show more
2026-09-06T10:54:33.794501+02:00 **** sshd-session[2061]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=149.102.130.252 user=root
2026-09-06T10:54:36.109029+02:00 **** sshd-session[2061]: Failed password for root from 149.102.130.252 port 48590 ssh2
2026-09-06T10:55:07.435682+02:00 **** sshd-session[2808]: Invalid user **** from 149.102.130.252 port 33602
2026-09-06T10:55:07.437046+02:00 **** sshd-session[2808]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=149.102.130.252
2026-09-06T10:55:09.473846+02:00 **** sshd-session[2808]: Failed password for invalid user **** from 149.102.130.252 port 33602 ssh2
show less
Brute-Force
SSH