๐ต๐น
Subnet Shadow Specter
2026-07-21 20:57:10
(7 hours ago)
[CRITICAL][Security Alert] Honeypot decoy endpoint triggered; malicious intent signature detected (T ...
show more
[CRITICAL][Security Alert] Honeypot decoy endpoint triggered; malicious intent signature detected (Tor Exit Node). [Method]: => GET. [Request]: / [User-Agent]: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36. [OS]: Apple. [IP Address]: 204.8.96.70. [IoA Datetime]: 2026-07-21 21:31:55 UTC +1.
show less
Bad Web Bot
Hacking
Open Proxy
Spoofing
Web App Attack
๐ต๐น
Subnet Shadow Specter
2026-07-21 20:31:50
(8 hours ago)
[CRITICAL][Security Alert] Honeypot decoy endpoint triggered; malicious intent signature detected (T ...
show more
[CRITICAL][Security Alert] Honeypot decoy endpoint triggered; malicious intent signature detected (Tor Exit Node). [Method]: => GET. [Request]: / [User-Agent]: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 [OS]: Unknown. [IP Address]: 204.8.96.70. [IoA Datetime]: 2026-07-21 21:31:50 UTC +1.
show less
Open Proxy
Port Scan
Hacking
Spoofing
Bad Web Bot
Exploited Host
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-07-21 18:13:41
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor E ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor Exit Node Traffic group 76).
show less
Hacking
Web App Attack
๐ช๐ธ
librebit
2026-07-21 06:57:03
(21 hours ago)
Brute force
Brute-Force
๐ฆ๐บ
oncord
2026-07-20 23:56:22
(1 day ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-07-20 00:26:18
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 204.8.96.70 (tor47.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 204.8.96.70 (tor47.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 20:26:13.363628 2026] [security2:error] [pid 2862:tid 2862] [client 204.8.96.70:36658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||annropp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "annropp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al1rJRsFgkFqHF1d0XMUAwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-19 05:57:23
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-07-17 22:31:49
(4 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 18:07:13
(4 days ago)
(mod_security) mod_security (id:210831) triggered by 204.8.96.70 (tor47.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:210831) triggered by 204.8.96.70 (tor47.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 14:07:05.588511 2026] [security2:error] [pid 1471798:tid 1471809] [client 204.8.96.70:56412] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.sylvestconsulting.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.sylvestconsulting.com"] [uri "/"] [unique_id "alpvSQOFikl49GEB1tKNQQAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-07-12 00:23:38
(1 week ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-10 02:19:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 204.8.96.70 (tor47.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 204.8.96.70 (tor47.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 22:19:19.376206 2026] [security2:error] [pid 28433:tid 28433] [client 204.8.96.70:33648] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ronjamestelevision.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ronjamestelevision.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alBWp5xhDBDWR_J4aNbvQQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-03 03:00:30
(2 weeks ago)
2026-07-02 20:00:04,298 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.70
2026-07-02 ...
show more
2026-07-02 20:00:04,298 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.70
2026-07-02 22:00:10,461 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.70
2026-07-03 00:01:00,279 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.70
2026-07-03 03:00:29,902 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.70
2026-07-03 06:00:29,478 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.70
show less
Brute-Force
๐ฎ๐น
VHosting
2025-09-17 12:18:16
(10 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
octageeks.com
2025-07-27 04:10:06
(11 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐ฆ๐บ
oncord
2025-07-26 19:09:23
(11 months ago)
Form spam
Web Spam