🇺🇸
wristhulk
2026-09-11 03:40:24
(3 hours ago)
Honeypot: VNC brute-force on OpenCanary honeypot (port 5900). Password not in common list (custom wo ...
show more
Honeypot: VNC brute-force on OpenCanary honeypot (port 5900). Password not in common list (custom wordlist).
show less
Brute-Force
🇺🇸
drewf.ink
2026-09-11 03:36:32
(3 hours ago)
[03:36] Attempted VNC authentication (DES challenge-response)
Hacking
Brute-Force
🇩🇪
Vegascosmetics
2026-08-15 18:53:07
(3 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: DEEP ATTACK: Recursive currentUrl nesting detected
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-06-25 01:09:21
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.88.98.34 (unn-149-88-98-34.datapacket.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 149.88.98.34 (unn-149-88-98-34.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 21:09:16.693336 2026] [security2:error] [pid 19737:tid 19737] [client 149.88.98.34:59204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chatgptfrance.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chatgptfrance.net"] [uri "/code.db"] [unique_id "ajx_vH2xsMAHKG3MDfVc4gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-06-03 21:15:00
(3 months ago)
WAF (2) - Malicious activity detected: URL probing.
Bad Web Bot
Web App Attack
Hacking
🇺🇦
URAN Publishing Service
2026-05-30 01:39:17
(3 months ago)
149.88.98.34 - - [30/May/2026:04:39:16 +0300] "GET /wp-content/ckeditor/plugins/imagebrowser/browser ...
show more
149.88.98.34 - - [30/May/2026:04:39:16 +0300] "GET /wp-content/ckeditor/plugins/imagebrowser/browser/browser.html HTTP/1.1" 404 763 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
149.88.98.34 - - [30/May/2026:04:39:17 +0300] "GET /wp-content/uploads/ckeditor/filemanager/browser/default/browser.html HTTP/1.1" 404 763 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
...
show less
Web App Attack
🇺🇸
nowyouknow
2026-05-25 00:07:26
(3 months ago)
(From [email protected] ) Hi,
Frustrated with swimsuits that block your perfect tan?
T ...
show more
(From [email protected] ) Hi,
Frustrated with swimsuits that block your perfect tan?
TanThrough swimwear is specially designed to give you the most even tan.
Your tan will look even and radiant with our swimwear.
Shop the unique tan-through swimwear at
https://tanthrough.online
With style and sun-kissed vibes.
show less
Phishing
Web Spam
🇿🇦
Tokolosh Hunters
2026-05-09 08:47:37
(4 months ago)
AutoBlockWindow-WordPress Bruteforce from NonZA-2026-05-09 08:47:36
Brute-Force
🇬🇧
consul.to
2026-05-09 06:45:27
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
🇪🇸
masterguru
2026-05-09 03:47:09
(4 months ago)
WordPress: User enumeration. Pattern match "(author\\\\= (1000-123)
Web App Attack
Anonymous
2026-04-30 17:29:07
(4 months ago)
(wordpress) Failed wordpress login from 149.88.98.34 (CA/Canada/unn-149-88-98-34.datapacket.com)
Brute-Force
🇺🇸
TPI-Abuse
2026-04-07 16:25:38
(5 months ago)
(mod_security) mod_security (id:240000) triggered by 149.88.98.34 (unn-149-88-98-34.datapacket.com): ...
show more
(mod_security) mod_security (id:240000) triggered by 149.88.98.34 (unn-149-88-98-34.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 12:25:30.356568 2026] [security2:error] [pid 1742964:tid 1742964] [client 149.88.98.34:33142] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||professionalpartyplanner.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "professionalpartyplanner.org"] [uri "/images/stories/themes.php"] [unique_id "adUv-oFQVMtT1uk2cSNIhQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2025-12-08 13:11:53
(9 months ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 13:36:50
(9 months ago)
(mod_security) mod_security (id:240000) triggered by 149.88.98.34 (unn-149-88-98-34.datapacket.com): ...
show more
(mod_security) mod_security (id:240000) triggered by 149.88.98.34 (unn-149-88-98-34.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 08:36:48.086857 2025] [security2:error] [pid 31617:tid 31617] [client 149.88.98.34:45756] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||elegantweddinginvitations.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "elegantweddinginvitations.net"] [uri "/images/stories/themes.php"] [unique_id "aTWC8E-iBqSDgG5ElUUwAwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 05:51:32
(9 months ago)
(mod_security) mod_security (id:240000) triggered by 149.88.98.34 (unn-149-88-98-34.datapacket.com): ...
show more
(mod_security) mod_security (id:240000) triggered by 149.88.98.34 (unn-149-88-98-34.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 00:51:25.202388 2025] [security2:error] [pid 10297:tid 10297] [client 149.88.98.34:55518] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||sailyourkayak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "sailyourkayak.com"] [uri "/images/stories/themes.php"] [unique_id "aTUV3TOD7DF6dE8uqbsy-AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack