Anonymous
2026-09-28 10:20:18
(5 days ago)
[honeypot-scan] 2026-09-28 10:20:18, Client: 216.81.248.25, Protocol: 6 (TCP), Service: HTTP, Activi ...
show more
[honeypot-scan] 2026-09-28 10:20:18, Client: 216.81.248.25, Protocol: 6 (TCP), Service: HTTP, Activity: bait-path scan (.env/.git probing)
show less
Web App Attack
๐ฉ๐ช
sfmet-admin
2026-09-28 03:44:10
(5 days ago)
216.81.248.25 - - [28/Sep/2026:03:44:09 +0000] "GET /.git/HEAD HTTP/2.0" 200 36 "-" "Mozilla/5.0 (Wi ...
show more
216.81.248.25 - - [28/Sep/2026:03:44:09 +0000] "GET /.git/HEAD HTTP/2.0" 200 36 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0"
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-09-27 18:34:47
(5 days ago)
301 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ธ๐ฌ
spydithreatintel
2026-09-27 12:53:26
(6 days ago)
Web honeypot: 1 HTTP request(s) incl. secret-probe. Example: GET /.git/HEAD
Web App Attack
๐บ๐ธ
ambor
2026-09-27 09:53:55
(6 days ago)
L0ss Honeypot: Git HEAD file access attempt. Path: /.git/HEAD
Web App Attack
๐ฉ๐ช
ramazan
2026-09-27 00:18:53
(6 days ago)
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.git/ /.git/hooks/post-commit.sample /.git/hooks/post-rec ...
show more
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.git/ /.git/hooks/post-commit.sample /.git/hooks/post-receive.sample /.git/logs/refs/heads/main /.git/logs/refs/heads/staging
show less
Web App Attack
Hacking
๐บ๐ธ
bazter.pro
2025-12-12 14:32:50
(9 months ago)
Auto-Ban [2025-12-09T06:44:22.815559]: Suspicious Datacenter (LightEdge Solutions); DC: LightEdge So ...
show more
Auto-Ban [2025-12-09T06:44:22.815559]: Suspicious Datacenter (LightEdge Solutions); DC: LightEdge Solutions [Paths: 3]
show less
Web App Attack
๐ฏ๐ต
Tom Tamagawa
2025-12-10 08:49:00
(9 months ago)
Probing for vulnerabilities.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 05:46:02
(9 months ago)
(mod_security) mod_security (id:210831) triggered by 216.81.248.25 (ip25.kcy.lh-nap.net): 1 in the l ...
show more
(mod_security) mod_security (id:210831) triggered by 216.81.248.25 (ip25.kcy.lh-nap.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 00:45:56.558325 2025] [security2:error] [pid 16519:tid 16519] [client 216.81.248.25:45632] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||lollytalk.com|F|4"] [data "Web Downloader"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "lollytalk.com"] [uri "/"] [unique_id "aTkJFHu4Mt-0S-R1VfGEdwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2025-12-10 05:12:25
(9 months ago)
216.81.248.25 - - [09/Dec/2025:23:12:07 -0600] "GET //www.wrsdeckdoctors.com/xmlrpc.php HTTP/1.1" 30 ...
show more
216.81.248.25 - - [09/Dec/2025:23:12:07 -0600] "GET //www.wrsdeckdoctors.com/xmlrpc.php HTTP/1.1" 301 3036 "-" "Mozilla/5.0 (X11; FreeBSD amd64) AppleWebKit/535.22+ (KHTML, like Gecko) Chromium/17.0.963.56 Chrome/17.0.963.56 Safari/535.22+ Epiphany/2.30.6"
216.81.248.25 - - [09/Dec/2025:23:12:07 -0600] "GET //www.wrsdeckdoctors.com/xmlrpc.php HTTP/1.1" 301 3039 "-" "SonyEricssonW580i/R6BC Browser/NetFront/3.3 Profile/MIDP-2.0 Configuration/CLDC-1.1"
216.81.248.25 - - [09/Dec/2025:23:12:07 -0600] "GET //www.wrsdeckdoctors.com/xmlrpc.php HTTP/1.1" 301 3042 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3269.3 Safari/537.36"
216.81.248.25 - - [09/Dec/2025:23:12:24 -0600] "GET //www.wrsdeckdoctors.com/xmlrpc.php HTTP/1.1" 301 449 "-" "Mozilla/5.0 (Linux; Android 8.0.0; moto e5 cruise Build/OCPS27.91-157-12) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.91 Mobile Safari/537.36"
216.81.248.25 - - [09/Dec/2025:23:12:24 -0600] "GET //www.wrsde
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 03:49:33
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.81.248.25 (ip25.kcy.lh-nap.net): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 216.81.248.25 (ip25.kcy.lh-nap.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 22:49:26.988106 2025] [security2:error] [pid 1818:tid 1818] [client 216.81.248.25:57378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neconebooks.com"] [uri "/home/mbechte3/public_html/wp-config.php"] [unique_id "aTjtxsTLL4KCLX3akeR5hgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-12-10 03:06:39
(9 months ago)
Request Overload (110)
Brute-Force
Web App Attack
๐บ๐ธ
technash
2025-12-09 22:03:00
(9 months ago)
Web app attack detection [ModSecurity]. Result: Dropped traffic.
Bad Web Bot
Web App Attack
๐บ๐ธ
AutoAddOnStore
2025-12-09 19:44:00
(9 months ago)
vulnerability scanner
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 18:50:46
(9 months ago)
(mod_security) mod_security (id:210831) triggered by 216.81.248.25 (ip25.kcy.lh-nap.net): 1 in the l ...
show more
(mod_security) mod_security (id:210831) triggered by 216.81.248.25 (ip25.kcy.lh-nap.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 13:50:42.788983 2025] [security2:error] [pid 31045:tid 31045] [client 216.81.248.25:56208] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||lukeschicago.com|F|4"] [data "EmailWolf"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "lukeschicago.com"] [uri "/lukeschicago.com/xmlrpc.php"] [unique_id "aThvghRNzkbkOpI3zg8n3AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack