🇳🇱
0xffffffff
2026-09-06 08:24:51
(3 days ago)
[2026-09-06 11:24:48.927913] [authz_core:error] [pid 872468:tid 132047620269760] [client 34.156.182. ...
show more
[2026-09-06 11:24:48.927913] [authz_core:error] [pid 872468:tid 132047620269760] [client 34.156.182.150:47356] AH01630: client denied by server configuration: /var/www/html/ , error_notes:wrong-host , URI:'/'
[2026-09-06 11:24:49.078755] [authz_core:error] [pid 872467:tid 132047569913536] [client 34.156.182.150:47362] AH01630: client denied by server configuration: /var/www/html/ , error_notes:wrong-host , URI:'/'
[2026-09-06 11:24:49.231578] [authz_core:error] [pid 872468:tid 132047553128128] [client 34.156.182.150:47366] AH01630: client denied by server configuration: /var/www/html/ , error_notes:wrong-host , URI:'/'
[2026-09-06 11:24:49.382746] [authz_core:error] [pid 872467:tid 132047595091648] [client 34.156.182.150:47376] AH01630: client denied by server configuration: /var/www/html/ , error_notes:wrong-host , URI:'/'
[2026-09-06 11:24:49.585094] [authz_core:error] [pid 872468:tid 132047578306240] [client 34.156.182.150:47380] AH01630: client denied by server configuration: /var/www/html/ , error_notes:
show less
Web App Attack
Bad Web Bot
🇦🇺
FEWA
2026-09-06 08:00:28
(3 days ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
🇺🇸
jfz-abuse
2026-09-06 07:29:57
(3 days ago)
fail2ban: apache-proxy
...
Web App Attack
🇩🇪
Serpentex
2026-09-06 07:05:47
(3 days ago)
34.156.182.150 - - [06/Sep/2026:09:05:41 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x94\xC ...
show more
34.156.182.150 - - [06/Sep/2026:09:05:41 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x94\xC7\x8B\xF0\xEE\x0F\x99\xE2U1\x06E\x8BP\xD6\xA9\xEBc+2\xA7%:\xCE|\xD0\x9E\x8D\xF3e\xE6\x7F A\x100)x\x06\xC0d|\xA8\x98i\xFF!LA/\xD7\x1D\x9Dw.\x1B\xE7\x07\xD0ya!\x805\x01\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
34.156.182.150 - - [06/Sep/2026:09:05:46 +0200] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-"
34.156.182.150 - - [06/Sep/2026:09:05:46 +0200] "\x91\x9D\xBA\xBA~\xE9Q\xE9\xAB=\xF5o\xBC\xE1\x07\xB1\xDC9\x97\xE9\xE2\xAF\xEC2_\x99\x94t\xD8\x85-\x8Dn\x03\x1B\xCF\x03\xD2\xF5\x17" 400 150 "-" "-"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
KayCee
2026-09-06 06:44:37
(3 days ago)
34.156.182.150 - - [06/Sep/2026:02:43:42 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03@\x10\x ...
show more
34.156.182.150 - - [06/Sep/2026:02:43:42 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03@\x10\x1C@I\x92W\xFC\xCF\xDE\xF2\x17\xE3'" 400 150 "-" "-" "-"
34.156.182.150 - - [06/Sep/2026:02:43:47 -0400] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-" "-"
34.156.182.150 - - [06/Sep/2026:02:43:48 -0400] "\x8C6c\x8Bj\xC4\xCD\xD9\xBE\x8F@S\xD8\x10\x1F;\xC6s\x1A0#\x13a\xBB\x92g#\x19\xF2 \xE0\xD2\x8B\xF8\x11 \x8E\xBC\xA1\x88\xD7\x04\xE9\xE9\x1C\xF1\xF9\x1E\x84\x1E}\xEF\x0E\xDD\xE6\xC8\xC5f\x88db\x8B\x92\xAD" 400 150 "-" "-" "-"
34.156.182.150 - - [06/Sep/2026:02:44:08 -0400] "\x00\x1E\xD9\x97\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x07version\x04bind\x00\x00\x10\x00\x03" 400 150 "-" "-" "-"
34.156.182.150 - - [06/Sep/2026:02:44:13 -0400] "\x03\x00\x00\x13\x0E\xE0\x00\x00\x00\x00\x00\x01\x00\x08\x00\x0B\x00\x00\x00" 400 150 "-" "-" "-"
34
...
show less
Web App Attack
🇳🇱
donarev419
2026-09-06 06:31:59
(3 days ago)
Connection to port 80 with data transfer.
Data preview: GET / HTTP/1.1
Host: 87.229.95.155:80
User ...
show more
Connection to port 80 with data transfer.
Data preview: GET / HTTP/1.1
Host: 87.229.95.155:80
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleW
show less
Port Scan
Hacking
🇫🇷
Entalpi.net
2026-09-06 06:12:19
(3 days ago)
Repeated requests against sensitive web endpoints
Web App Attack
🇩🇪
Starburst SysOp Team
2026-09-06 05:47:09
(3 days ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-nue6-2)
Hacking
Bad Web Bot
🇳🇱
ItsJustStan
2026-09-06 05:25:17
(3 days ago)
Multi-protocol port scanner sending binary payloads to HTTP port
Port Scan
🇷🇺
genokrad
2026-09-06 05:21:54
(3 days ago)
Website scan TCP 80/443 "/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KH"
Port Scan
Web App Attack
🇺🇸
gu-alvareza
2026-09-06 05:06:28
(3 days ago)
Nmap.Script.Scanner
Port Scan
🇩🇪
raspi4
2026-09-06 04:32:55
(3 days ago)
Fail2Ban Ban Triggered
Brute-Force
Web App Attack
🇭🇳
remurillod80
2026-09-06 03:50:27
(3 days ago)
[Sat Sep 05 21:50:27.336089 2026] [security2:error] [pid 953439:tid 953439] [client 34.156.182.150:2 ...
show more
[Sat Sep 05 21:50:27.336089 2026] [security2:error] [pid 953439:tid 953439] [client 34.156.182.150:2714] ModSecurity: Warning. Pattern match "(?:^([\\\\d.]+|\\\\[[\\\\da-f:]+\\\\]|[\\\\da-f:]+)(:[\\\\d]+)?$)" at REQUEST_HEADERS:Host. [file "/etc/modsecurity/crs/current/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "773"] [id "920350"] [msg "Host header is a numeric IP address"] [data "186.32.240.17:80"] [severity "WARNING"] [ver "OWASP_CRS/4.27.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "186.32.240.17"] [uri "/"] [unique_id "apzjAxbrYtMI2q-62dNzCAAAAAw"]
[Sat Sep 05 21:50:27.338103 2026] [security2:error] [pid 953439:tid 953439] [client 34.156.182.150:2714] ModSecurity: Warning. Unconditional match in SecAction. [file "/etc/modsecurity/crs/current/rules/RESPONSE-980-CORRELATION.conf"] [line "99"] [id "98017
...
show less
Web Spam
Hacking
SQL Injection
Brute-Force
Web App Attack
🇯🇵
VXG-NET
2026-09-06 03:50:09
(3 days ago)
port=80, indicator_type=hacktool
Hacking
🇯🇵
HeliJP
2026-09-06 03:45:50
(3 days ago)
2026-09-06T03:16:35Z - Recognized attacks\bad behavior from IP address 34.156.182.150 on port 443\80 ...
show more
2026-09-06T03:16:35Z - Recognized attacks\bad behavior from IP address 34.156.182.150 on port 443\80 (7 daily hits): client denied by server configuration
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Web App Attack