๐บ๐ธ
gui-ying233
2026-09-18 21:18:50
(3 days ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-09-13 06:10:10
(1 week ago)
Distributed web scraper targeting /store/filtered/ on www.mywineandspirits.com. Residential proxy - ...
show more
Distributed web scraper targeting /store/filtered/ on www.mywineandspirits.com. Residential proxy - IP+timestamp provided for ISP DHCP log attribution.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐น๐ท
SeczarSecureOps
2026-09-12 19:01:55
(1 week ago)
Seczar SecureOps โ Port Scan Detection (127 events) โ quarantined 43200m on DPYS_Master
Port Scan
๐บ๐ธ
kosada.com
2026-08-26 21:55:05
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-08-25 15:26:26
(4 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-08-09 22:42:15
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-25 19:28:14
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-06-29 08:09:14
(2 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Exploited Host
Bad Web Bot
๐จ๐ญ
SOC [GOLINE SA]
2025-08-29 15:02:33
(1 year ago)
Security Alert: 21 port scan attempt(s) from 188.219.4.242; Ports: *; Evidence: 2025-08-29T17:01:21. ...
show more
Security Alert: 21 port scan attempt(s) from 188.219.4.242; Ports: *; Evidence: 2025-08-29T17:01:21.974677+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=1520 DF PROTO=TCP SPT=5757 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-08-29T17:01:22.156406+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=22279 DF PROTO=TCP SPT=5767 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-08-29T17:01:22.995866+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=1521 DF PROTO=TCP SPT=5757 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-08-29T17:01:23.235857+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242...
show less
Port Scan
๐ณ๐ฑ
exxos
2025-08-12 00:03:01
(1 year ago)
HTTP1.x attacks
DDoS Attack
๐จ๐ญ
SOC [GOLINE SA]
2025-07-18 14:38:28
(1 year ago)
Security Alert: 21 port scan attempt(s) from 188.219.4.242; Ports: *; Evidence: 2025-07-18T16:37:05. ...
show more
Security Alert: 21 port scan attempt(s) from 188.219.4.242; Ports: *; Evidence: 2025-07-18T16:37:05.016597+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=43040 DF PROTO=TCP SPT=11907 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-07-18T16:37:05.202620+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=20635 DF PROTO=TCP SPT=11920 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-07-18T16:37:06.074209+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=43041 DF PROTO=TCP SPT=11907 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-07-18T16:37:06.224107+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219....
show less
Port Scan
๐จ๐ญ
SOC [GOLINE SA]
2025-07-18 10:55:24
(1 year ago)
Security Alert: 21 port scan attempt(s) from 188.219.4.242; Ports: *; Evidence: 2025-07-18T12:52:36. ...
show more
Security Alert: 21 port scan attempt(s) from 188.219.4.242; Ports: *; Evidence: 2025-07-18T12:52:36.810291+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=63530 DF PROTO=TCP SPT=16398 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-07-18T12:52:36.862374+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=31259 DF PROTO=TCP SPT=16401 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-07-18T12:52:36.862625+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4.242 DST=185.54.81.15 LEN=60 TOS=0x08 PREC=0x00 TTL=64 ID=4769 DF PROTO=TCP SPT=56574 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 2025-07-18T12:52:36.912762+02:00 www kernel: Firewall: *Port Flood* IN=eth0 OUT= MAC=00:50:56:9f:99:4f:00:50:56:9f:c3:6b:08:00 SRC=188.219.4...
show less
Port Scan
๐จ๐ญ
SOC [GOLINE SA]
2025-02-25 04:34:42
(1 year ago)
(mod_security) mod_security (id:97001) triggered by 188.219.4.242 (IT/Italy/Lombardy/Milan/net-188-2 ...
show more
(mod_security) mod_security (id:97001) triggered by 188.219.4.242 (IT/Italy/Lombardy/Milan/net-188-219-4-242.cust.vodafonedsl.it/[AS30722 Vodafone Italia S.p.A.]): 1 in the last 3600 secs; IP: 188.219.4.242; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Tue Feb 25 05:34:40.452750 2025] [security2:error] [pid 1097371:tid 1097432] [client 188.219.4.242:26423] [client 188.219.4.242] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(?i:(HTTrack|wget|curl|nikto|fuzz))" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/modsecurity.conf"] [line "67"] [id "97001"] [msg "Bad user agent detected."] [hostname "www.goline.ch"] [uri "/speedtest/random4000x4000.jpg"] [unique_id "Z71IYL_BDD6bA245aTzUWwAAABE"]
show less
Brute-Force
๐จ๐ญ
SOC [GOLINE SA]
2025-02-24 04:32:56
(1 year ago)
(mod_security) mod_security (id:97001) triggered by 188.219.4.242 (IT/Italy/Lombardy/Milan/net-188-2 ...
show more
(mod_security) mod_security (id:97001) triggered by 188.219.4.242 (IT/Italy/Lombardy/Milan/net-188-219-4-242.cust.vodafonedsl.it/[AS30722 Vodafone Italia S.p.A.]): 1 in the last 3600 secs; IP: 188.219.4.242; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Mon Feb 24 05:32:53.009062 2025] [security2:error] [pid 816611:tid 816696] [client 188.219.4.242:51567] [client 188.219.4.242] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(?i:(HTTrack|wget|curl|nikto|fuzz))" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/modsecurity.conf"] [line "67"] [id "97001"] [msg "Bad user agent detected."] [hostname "www.goline.ch"] [uri "/speedtest/random750x750.jpg"] [unique_id "Z7v2dYYBS2g8OOGaGXncWQAAAEY"]
show less
Brute-Force
๐จ๐ญ
SOC [GOLINE SA]
2025-02-23 09:05:49
(1 year ago)
(mod_security) mod_security (id:97001) triggered by 188.219.4.242 (IT/Italy/Lombardy/Milan/net-188-2 ...
show more
(mod_security) mod_security (id:97001) triggered by 188.219.4.242 (IT/Italy/Lombardy/Milan/net-188-219-4-242.cust.vodafonedsl.it/[AS30722 Vodafone Italia S.p.A.]): 1 in the last 3600 secs; IP: 188.219.4.242; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Sun Feb 23 10:05:44.837737 2025] [security2:error] [pid 537340:tid 537390] [client 188.219.4.242:56329] [client 188.219.4.242] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(?i:(HTTrack|wget|curl|nikto|fuzz))" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/modsecurity.conf"] [line "67"] [id "97001"] [msg "Bad user agent detected."] [hostname "www.goline.ch"] [uri "/speedtest/random1500x1500.jpg"] [unique_id "Z7rk6ClQRvi1QTMzPosKcwAAAAc"]
show less
Brute-Force