Anonymous
2026-08-27 03:53:06
(1 month ago)
denied traffic to a honeypot network. destination port 53.
Port Scan
Hacking
๐ช๐ธ
el-brujo
2026-07-24 18:05:54
(2 months ago)
07/24/2026-20:05:54.713671 185.132.187.133 Protocol: 6 ET SCAN Behavioral Unusually fast Terminal Se ...
show more
07/24/2026-20:05:54.713671 185.132.187.133 Protocol: 6 ET SCAN Behavioral Unusually fast Terminal Server Traffic Potential Scan or Infection (Inbound)
show less
Hacking
๐บ๐ธ
threatintelligence_bvc
2026-06-29 05:26:17
(2 months ago)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 12:51:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 08:51:53.783757 2026] [security2:error] [pid 23474:tid 23474] [client 185.132.187.133:53113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starfateofficial.com"] [uri "/.git/HEAD"] [unique_id "aiF06co9nvruUUW_JVp36gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 09:50:08
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 05:49:59.251325 2026] [security2:error] [pid 12094:tid 12094] [client 185.132.187.133:35111] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewhispertwins.com"] [uri "/.git/HEAD"] [unique_id "aiFKR9ySME3kOvU3MmeKfwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 09:30:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 05:30:14.213411 2026] [security2:error] [pid 24112:tid 24112] [client 185.132.187.133:45155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nhgrange.org"] [uri "/.git/HEAD"] [unique_id "aiFFppYCrHLMLhfVicm-0AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 09:00:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 05:00:31.542478 2026] [security2:error] [pid 22885:tid 22885] [client 185.132.187.133:33163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rschaefer.net"] [uri "/.git/"] [unique_id "aiE-rzCkxkU3EF7VOqVSmAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 08:33:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 04:33:02.677814 2026] [security2:error] [pid 26390:tid 26440] [client 185.132.187.133:33201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rdumail.us"] [uri "/.git/config"] [unique_id "aiE4Pt9QGWx9p-7okeG8XAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-04 08:07:10
(3 months ago)
Abuse Detected (4)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 07:21:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 03:21:11.192630 2026] [security2:error] [pid 1841:tid 1841] [client 185.132.187.133:62157] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mydarklady.com"] [uri "/.git/HEAD"] [unique_id "aiEnZ2lOVsk8VsYgVYY1EgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-05-06 09:03:32
(4 months ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/filester/assets/css/404.php /wp-conte ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/filester/assets/css/404.php /wp-content/plugins/shell/index.php /wp-content/plug ...
show less
Web App Attack
๐ฟ๐ฆ
Tokolosh Hunters
2026-04-30 03:17:47
(4 months ago)
AutoBlockWindow-Known bad useragent query-2026-04-30 03:17:46
Bad Web Bot
๐บ๐ธ
mnsf
2026-04-29 17:05:16
(4 months ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-29 16:23:29
(4 months ago)
185.132.187.133 - - [29/Apr/2026:19:23:28 +0300] "GET /wp-content/plugins/WordPressCore/include.php ...
show more
185.132.187.133 - - [29/Apr/2026:19:23:28 +0300] "GET /wp-content/plugins/WordPressCore/include.php HTTP/1.1" 404 706 "-" "Go-http-client/1.1"
185.132.187.133 - - [29/Apr/2026:19:23:29 +0300] "GET /wp-content/plugins/dummyyummy/wp-signup.php HTTP/1.1" 404 706 "-" "Go-http-client/1.1"
...
show less
Web App Attack
Anonymous
2026-04-16 21:07:53
(5 months ago)
PSCSERV WPSCAN 185.132.187.133
Bad Web Bot
Web App Attack