๐บ๐ธ
Epimetheus
2026-09-16 15:50:41
(41 minutes ago)
Honeypot hit! 1 attempts in the last 5 minutes.
Sample UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; ...
show more
Honeypot hit! 1 attempts in the last 5 minutes.
Sample UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:118.0.2) Gecko/20100101 Firefox/118.0.2
show less
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:20:51
(4 hours ago)
(mod_security) mod_security (id:210350) triggered by 20.255.75.24 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.255.75.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:20:44.289686 2026] [security2:error] [pid 21482:tid 21482] [client 20.255.75.24:1551] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||northwestarbor-culture.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "northwestarbor-culture.com"] [uri "/"] [unique_id "aqqJnMMflqwHm9qONag_bwAAAAY"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-16 07:52:58
(8 hours ago)
[WedSep1609:52:54.0969092026][security2:error][pid273357:tid273427][client20.255.75.24:0]ModSecurity ...
show more
[WedSep1609:52:54.0969092026][security2:error][pid273357:tid273427][client20.255.75.24:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"rvengineering.ch\"][uri\"/xmlrpc.php\"][unique_id\"aqpK1vUpgbx4fnObbDicMwAAAI0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:15:11
(9 hours ago)
(mod_security) mod_security (id:210350) triggered by 20.255.75.24 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.255.75.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:15:02.158988 2026] [security2:error] [pid 5837:tid 5837] [client 20.255.75.24:1479] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||happyvalleynh.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "happyvalleynh.org"] [uri "/"] [unique_id "aqpB9os3Zd8PLEvWHWeYKQAAAAM"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-09-16 06:06:28
(10 hours ago)
L0ss Honeypot: WordPress XML-RPC attack attempt. Path: /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-16 03:58:35
(12 hours ago)
Unauthorized access attempts:
[GET] /xmlrpc.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7 ...
show more
Unauthorized access attempts:
[GET] /xmlrpc.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.85 Safari/537.36
show less
Web App Attack
๐ท๐ด
iulianh
2026-09-16 02:56:33
(13 hours ago)
80,443
Brute-Force
SSH
๐ณ๐ฑ
MyGlobalFlowers
2026-09-16 01:23:57
(15 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-16 00:40:36
(15 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /[a-z0-9]{1,12}\.php (Match: /xmlrpc.php)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:29:35
(16 hours ago)
(mod_security) mod_security (id:210350) triggered by 20.255.75.24 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.255.75.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:29:28.150378 2026] [security2:error] [pid 28348:tid 28348] [client 20.255.75.24:1244] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||albertmassaad.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "albertmassaad.com"] [uri "/"] [unique_id "aqni6BvRZ_6g2y_cZYpTrgAAAA0"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(16 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐จ๐ญ
zynex
2026-09-16 00:00:16
(16 hours ago)
URL Probing: /xmlrpc.php
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-15 22:48:33
(17 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
ambor
2026-09-15 21:29:48
(19 hours ago)
Honeypot access: WordPress XML-RPC attack attempt. Path: /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:36:19
(19 hours ago)
(mod_security) mod_security (id:210350) triggered by 20.255.75.24 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.255.75.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:36:15.789563 2026] [security2:error] [pid 17680:tid 17680] [client 20.255.75.24:1228] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||summithost.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "summithost.com"] [uri "/"] [unique_id "aqmsP8ZEV92bp7JRqEl1lQAAAA8"], referer: https://www.reddit.com/
show less
Brute-Force
Bad Web Bot
Web App Attack