๐ซ๐ฎ
mnazibo
2026-10-04 12:15:10
(2 days ago)
Date: Oct 04 15:09:15 2026 EAT | Reported IP: 34.79.183.83 mod_security | id: 920350 | BE/usernameab ...
show more
Date: Oct 04 15:09:15 2026 EAT | Reported IP: 34.79.183.83 mod_security | id: 920350 | BE/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Host header is a numeric IP address
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
solantex
2026-10-04 12:14:44
(2 days ago)
Malformed and abusive traffic directed at Solantex services.
Port Scan
๐บ๐ธ
distorx
2026-10-04 11:36:34
(2 days ago)
[04/Oct/2026:11:36:33 +0000] 400 - GET http 209.141.57.83 "/" [Client 34.79.183.83] [Length 252] [Gz ...
show more
[04/Oct/2026:11:36:33 +0000] 400 - GET http 209.141.57.83 "/" [Client 34.79.183.83] [Length 252] [Gzip -] "Mozilla/5.0 (compatible)" "-"
...
show less
Port Scan
Bad Web Bot
๐ณ๐ฑ
Eric
2026-10-04 10:51:24
(2 days ago)
[Sun Oct 04 10:51:22.677988 2026] [security2:error] [pid 3508309:tid 3508309] [client 34.79.183.83:2 ...
show more
[Sun Oct 04 10:51:22.677988 2026] [security2:error] [pid 3508309:tid 3508309] [client 34.79.183.83:21264] [client 34.79.183.83] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "asIvqpRn4YgsVYIcItltsgAAAA4"]
[Sun Oct 04 10:51:22.829923 2026] [security2:error] [pid 3697143:tid 3697143] [client 34.79.183.83:8408] [client 34.79.183.83] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [ms
...
show less
Hacking
Web App Attack
๐ช๐ช
Selckie
2026-10-04 10:50:47
(2 days ago)
fail2ban: NGINX unusual impact
Web App Attack
Anonymous
2026-10-04 10:45:15
(2 days ago)
tls scan
Port Scan
๐น๐ญ
MWA SOC
2026-10-04 09:41:40
(2 days ago)
Hacking
๐ป๐ณ
edata-vn
2026-10-04 09:34:04
(2 days ago)
"GET / HTTP/1.1" 444 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Geck ...
show more
"GET / HTTP/1.1" 444 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
initsol
2026-10-04 09:25:29
(2 days ago)
[Sun Oct 04 11:25:28.760167 2026] [authz_core:error] [pid 2539299:tid 2539299] [client 34.79.183.83: ...
show more
[Sun Oct 04 11:25:28.760167 2026] [authz_core:error] [pid 2539299:tid 2539299] [client 34.79.183.83:56388] AH01630: client denied by server configuration: /var/www/
[Sun Oct 04 11:25:28.914429 2026] [authz_core:error] [pid 2539304:tid 2539304] [client 34.79.183.83:56404] AH01630: client denied by server configuration: /var/www/
[Sun Oct 04 11:25:29.071221 2026] [authz_core:error] [pid 2539307:tid 2539307] [client 34.79.183.83:56414] AH01630: client denied by server configuration: /var/www/
...
show less
Brute-Force
๐บ๐ธ
ratcarcher-labs
2026-10-04 07:49:19
(2 days ago)
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=bot_scanner risk=75 attacks=7 depth=1 ...
show more
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=bot_scanner risk=75 attacks=7 depth=1 node=node-us-east canary=no human_score=50 agentic=15 cc=BE asn=Google LLC | Data provided by Ratcarcher Labs ยท https://ratcarcher-labs.com ยท docs https://api.ratcarcher-labs.com/api/v1/public/docs
show less
Port Scan
Bad Web Bot
Anonymous
2026-10-04 07:47:05
(2 days ago)
Web application attack detected.
Web App Attack
๐จ๐ฆ
lakered
2026-10-04 07:43:38
(2 days ago)
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol ...
show more
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evidence: High-Criminality-Signature (ja4:t13i250900 - Ratio:0.93), High-Criminality-Signature (p0f:*:64:0:*:mss*30,7:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.98), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:66998m)
show less
Port Scan
Exploited Host
๐ซ๐ฎ
23p02732
2026-10-04 07:39:01
(2 days ago)
Mailserver and mailaccount attacks
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ง๐ท
diego
2026-10-04 07:16:11
(2 days ago)
[probe-168-134] 2026-10-04 07:00:04, Client: 34.79.183.83, Protocol: 6, Unauthorized activity to HTT ...
show more
[probe-168-134] 2026-10-04 07:00:04, Client: 34.79.183.83, Protocol: 6, Unauthorized activity to HTTP: GET /
show less
Web App Attack
๐ซ๐ท
masterguru
2026-10-04 07:08:12
(2 days ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-197)
Hacking
Bad Web Bot