๐ท๐บ
Mga Admin
2026-09-23 15:55:57
(6 hours ago)
16.216.88.4 - - [23/Sep/2026:22:55:56 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs2813964 H ...
show more
16.216.88.4 - - [23/Sep/2026:22:55:56 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs2813964 HTTP/1.1" 400 34 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-09-23 11:17:50
(10 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: apm.astropot.site | URI: /backup.sql | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฏ๐ต
yoren
2026-09-23 07:10:43
(14 hours ago)
Automated report from JTZL's Bot Maze: crawled hidden bot-trap pages and crossed the site's configur ...
show more
Automated report from JTZL's Bot Maze: crawled hidden bot-trap pages and crossed the site's configured blocking threshold.
show less
Bad Web Bot
๐ฎ๐ฉ
hermawan
2026-09-23 05:48:35
(16 hours ago)
[Wed Sep 23 12:43:49.719832 2026] [security2:error] [pid 56018:tid 139977665009344] [client 16.216.8 ...
show more
[Wed Sep 23 12:43:49.719832 2026] [security2:error] [pid 56018:tid 139977665009344] [client 16.216.88.4:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:user-agent. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "274"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555559488-infografis-suhu-dingin-di-malang-dan-sekitarnya HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555559488-infografis-suhu-dingin-di-malang-dan-sekitarnya"] [unique_id "arNnFQNxbffsbXzj7PwyeQAAAEk"] [staklim-jatim.bmkg.go.id] [staklim-j
...
show less
Email Spam
Hacking
๐ฉ๐ช
netclix.gr
2026-09-23 02:08:05
(20 hours ago)
(PERMBLOCK) 16.216.88.4 (US/United States/reflectionbot-88-4.reflection.ai) has had more than 2 temp ...
show more
(PERMBLOCK) 16.216.88.4 (US/United States/reflectionbot-88-4.reflection.ai) has had more than 2 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐บ๐ธ
LSPCCU
2026-09-23 00:45:59
(21 hours ago)
TSEC Honeypot Network report. Threat score: 66/100. Categories: DDoS Attack, Port Scan, Hacking, Bru ...
show more
TSEC Honeypot Network report. Threat score: 66/100. Categories: DDoS Attack, Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: h0neytr4p. Context: 16.216.88.4 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
DDoS Attack
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
๐ท๐บ
genokrad
2026-09-23 00:39:28
(21 hours ago)
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible ...
show more
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; R"
show less
Port Scan
Web App Attack
๐ฎ๐ฉ
hermawan
2026-09-22 04:36:16
(1 day ago)
[Tue Sep 22 11:36:14.895282 2026] [security2:error] [pid 62511:tid 140304722048704] [client 16.216.8 ...
show more
[Tue Sep 22 11:36:14.895282 2026] [security2:error] [pid 62511:tid 140304722048704] [client 16.216.88.4:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:user-agent. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "274"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555563287-prediksi-bulanan-curah-hujan-bulan-september-tahun-2026-update-dari-analisis-bulan-juni-tahun-2026-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555563287-prediksi-bulanan-curah-hujan-bulan-september-ta
...
show less
Email Spam
Hacking
Anonymous
2026-09-22 01:52:12
(1 day ago)
Automated report (2026-09-21T21:52:12-04:00). Scraper detected.
Bad Web Bot
๐ท๐บ
Mga Admin
2026-09-21 23:46:03
(1 day ago)
16.216.88.4 - - [22/Sep/2026:06:46:01 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs535396050 ...
show more
16.216.88.4 - - [22/Sep/2026:06:46:01 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs535396050 HTTP/1.1" 400 34 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ท๐บ
genokrad
2026-09-21 23:23:58
(1 day ago)
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible ...
show more
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; R"
show less
Port Scan
Web App Attack
Anonymous
2026-09-21 16:00:13
(2 days ago)
16.216.88.4 www.rolistore.com - [20/Sep/2026:20:09:57 -0600] "GET /control-nintendo-switch-ancient-a ...
show more
16.216.88.4 www.rolistore.com - [20/Sep/2026:20:09:57 -0600] "GET /control-nintendo-switch-ancient-archer?tag=nintendo%20switch HTTP/1.1" 200 754350 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"\n16.216.88.4 www.rolistore.com - [21/Sep/2026:03:35:26 -0600] "GET /control-nsw-mario-joy-rojo?tag=rojo HTTP/1.1" 200 765253 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"\n16.216.88.4 www.rolistore.com - [21/Sep/2026:10:00:12 -0600] "GET /index.php?route=product/search&tag=iluminacion HTTP/1.1" 200 652275 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐ฉ๐ช
netclix.gr
2026-09-21 06:16:39
(2 days ago)
(bot_qv) Bot Scraping QuickView 16.216.88.4 (US/United States/-): 1 in the last 4600 secs; Ports: *; ...
show more
(bot_qv) Bot Scraping QuickView 16.216.88.4 (US/United States/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 16.216.88.4 - - [21/Sep/2026:09:16:36 +0300] "GET /index.php?dispatch=products.quick_view&n_items=4271%2C4272%2C4266%2C4267%2C4268%2C4539%2C4067&prev_url=index.php%3Fsort_by%3Dprice%26sort_order%3Dasc%26sl%3Del%26dispatch%3Dcategories.view%26category_id%3D321&product_id=4272 HTTP/2.0" 302 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"
show less
Port Scan
Anonymous
2026-09-21 06:05:18
(2 days ago)
Blocked: Reason='Suspicious traffic score=65 (review-based detection)'; Requests=3
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 03:34:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 16.216.88.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 16.216.88.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:34:08.370543 2026] [security2:error] [pid 25858:tid 25858] [client 16.216.88.4:8192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.justinrudd.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.justinrudd.com"] [uri "/about.html/mailto:[email protected] "] [unique_id "arClsB2ZosnhT4p3nJVlwwAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack