๐ฎ๐น
CoreTech srl
2026-09-14 03:18:47
(6 days ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_server_contact
Hacking
๐ฉ๐ช
tall1oN
2026-09-14 03:14:32
(6 days ago)
34.150.146.142 - - [14/Sep/2026:05:14:31 +0200] "POST /graphql HTTP/2.0" 405 559 "https://cdn.demons ...
show more
34.150.146.142 - - [14/Sep/2026:05:14:31 +0200] "POST /graphql HTTP/2.0" 405 559 "https://cdn.demons-gaming.cc" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "cdn.demons-gaming.cc"
34.150.146.142 - - [14/Sep/2026:05:14:31 +0200] "POST /api/graphql HTTP/2.0" 405 559 "https://cdn.demons-gaming.cc" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "cdn.demons-gaming.cc"
...
show less
Web App Attack
Port Scan
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-13 12:08:03
(1 week ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 5s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 10:08:45
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.150.146.142 (142.146.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.150.146.142 (142.146.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 06:08:39.497329 2026] [security2:error] [pid 897:tid 897] [client 34.150.146.142:55266] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vanmeter.cc|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vanmeter.cc"] [uri "/rclone.conf"] [unique_id "aqZ2JxAUg8nZIpO4C0UzBgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
ZEROVOX
2026-09-13 08:39:20
(1 week ago)
CrowdSec: crowdsecurity/http-probing detected
Web App Attack
๐ฉ๐ช
zUnlegit
2026-09-13 08:17:46
(1 week ago)
Automated web scanner requested sensitive path: /@fs/src/.env
Web App Attack
๐ซ๐ฎ
pixiekat
2026-09-13 07:34:33
(1 week ago)
[Sun Sep 13 08:34:32.439397 2026] [security2:error] [pid 745953:tid 745972] [remote 34.150.146.142:5 ...
show more
[Sun Sep 13 08:34:32.439397 2026] [security2:error] [pid 745953:tid 745972] [remote 34.150.146.142:55858] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "integraldata.cc"] [uri "/"] [unique_id "aqZSCL-_uf9SaBmqGR_-BAAAxxE"]
[Sun Sep 13 08:34:32.833934 2026] [security2:error] [pid 745953:tid 745978] [remote 34.150.146.142:55858] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWA
...
show less
Web App Attack
๐ณ๐ฑ
tmiland
2026-09-13 06:09:51
(1 week ago)
(nginx_404) Dot directory Honeypot Trap 34.150.146.142 (US/United States/142.146.150.34.bc.googleuse ...
show more
(nginx_404) Dot directory Honeypot Trap 34.150.146.142 (US/United States/142.146.150.34.bc.googleusercontent.com): 2 in the last 3600 secs; IP: 34.150.146.142; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.150.146.142 - - [13/Sep/2026:08:09:46 +0200] "GET /.env.production HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 34.150.146.142 - - [13/Sep/2026:08:09:46 +0200] "GET /.env.local HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
show less
Brute-Force
๐บ๐ธ
Cherryh4ck
2026-09-13 03:41:18
(1 week ago)
Blocked by UFW [8443/tcp] | SPT: 33118 | TTL: 60 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sef ...
show more
Blocked by UFW [8443/tcp] | SPT: 33118 | TTL: 60 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
mnsf
2026-09-13 02:05:05
(1 week ago)
Too many Status 40X (13)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-13 02:04:33
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.ovh | URI: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-13 01:56:09
(1 week ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-13 01:31:04
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
Aetherweb Ark
2026-09-13 01:23:52
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.150.146.142 (US/United States/142.146.150.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.150.146.142 (US/United States/142.146.150.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 01:09:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.150.146.142 (142.146.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.146.142 (142.146.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:08:55.383408 2026] [security2:error] [pid 29828:tid 29866] [client 34.150.146.142:43696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "btoelsalvador.com"] [uri "/css../.env"] [unique_id "aqX3p2v6daTh7iWDgkY6DgAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack