Anonymous
2026-10-05 00:45:51
(1 day ago)
Large-scale coordinated botnet (8M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show more
Large-scale coordinated botnet (8M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]): Retaliation after theft; Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]): Employed by Angara Technologies Group | Offpeak: Sessionless Catalog Access Blocked: /wishlist/index/add/product/11343/form_key/DQ0XgmZuC97UQkDu/ | UA: Opera/8.85.(X11; Linux i686; pl-PL) Presto/2.9.181 Version/11.00 | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-16 09:04:58
(2 weeks ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ซ๐ท
arsonist
2026-08-31 12:46:36
(1 month ago)
[fail2ban]
2026-08-31T12:46:35.648487+00:00 arson caddy[1890453]: {"level":"info","ts":1788180395.64 ...
show more
[fail2ban]
2026-08-31T12:46:35.648487+00:00 arson caddy[1890453]: {"level":"info","ts":1788180395.6484077,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"212.237.122.125","remote_port":"58794","client_ip":"212.237.122.125","proto":"HTTP/2.0","method":"GET","host":"git.tc14.space","uri":"/tc14/trailblazer-colony-14/src/commit/958d56f5c6bb0991a3e64186817379627c4b2e39/.envrc","headers":{"Sec-Ch-Ua-Platform":["\"macOS\""],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Fetch-Site":["same-origin"],"Sec-Fetch-Mode":["navigate"],"Cache-Control":["max-age=0"],"Sec-Ch-Ua":["\"Not_A Brand\";v=\"8\", \"Chromium\";v=\"145\", \"Google Chrome\";v=\"145\""],"Sec-Fetch-User":["?1"],"Sec-Fetch-Dest":["document"],"Referer":["https://git.tc14.space/tc14/trailblazer-colony-14/src/commit/958d56f5c6bb0991a3e64186817379627c4b2e39"],"Accept-Language":["zh-CN,
...
show less
Bad Web Bot
๐ธ๐ช
triplecode
2026-07-31 22:19:45
(2 months ago)
Reported from hMailServer
Hacking
Anonymous
2026-07-19 15:43:05
(2 months ago)
[osotir.org] httpd-storefront-action-burst: sites=www.ear-books.com; logs=/var/log/httpd/domains/ear ...
show more
[osotir.org] httpd-storefront-action-burst: sites=www.ear-books.com; logs=/var/log/httpd/domains/ear-books.com.log; samples=burst_window=1m | distinct_ips=18 | action_types=2
show less
Hacking
Web App Attack
๐ซ๐ท
MatStef132
2026-06-21 21:26:03
(3 months ago)
MatShield L7: blocked on mathost.eu (ua-quarantined)
Bad Web Bot
๐ฆ๐บ
MAGIC
2026-05-15 05:24:51
(4 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-01 03:46:33
(5 months ago)
(mod_security) mod_security (id:240950) triggered by 212.237.122.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240950) triggered by 212.237.122.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 23:46:28.014862 2026] [security2:error] [pid 32066:tid 32066] [client 212.237.122.125:44540] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||beckersystems.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "beckersystems.net"] [uri "/beckerwiki/index.php"] [unique_id "afQiFDVWQ2OOMo6jsMRoewAAAA8"], referer: http://beckersystems.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 20:50:31
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 212.237.122.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 212.237.122.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 16:50:24.092941 2026] [security2:error] [pid 243554:tid 243554] [client 212.237.122.125:32186] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||patrick.grimone.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "patrick.grimone.com"] [uri "/German/Europe Day 4/Thumbs.db"] [unique_id "aeaRkC9FUT0fqy3WXLy4IAAAAAk"], referer: https://patrick.grimone.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-04-02 00:27:26
(6 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ท๐ด
clauss
2026-03-23 02:04:46
(6 months ago)
IP reached maximum auth failures for a one day block
Brute-Force
๐บ๐ธ
kosada.com
2026-03-16 09:12:52
(6 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
SiliSoftware
2026-03-15 05:23:47
(6 months ago)
/phpBB3/viewtopic.php?f=4&t=732&p=2245
Web App Attack
๐น๐ท
rtbh.com.tr
2026-03-07 20:11:56
(6 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
Anonymous
2025-11-25 08:47:47
(10 months ago)
scanning http requests from known botnet
Web App Attack