๐ซ๐ฎ
FDC
2026-05-26 01:30:46
(4 months ago)
Malicious activity from 5.255.103.188 detected by FDC honeypots. Categories: 15,21. 120 events in la ...
show more
Malicious activity from 5.255.103.188 detected by FDC honeypots. Categories: 15,21. 120 events in last 24h.
show less
Hacking
Web App Attack
๐ฉ๐ช
heyzg
2026-05-16 16:30:16
(4 months ago)
API honeypot | LLMjacking (Ollama) | 88 HTTP, 37s | tactics: outbound scan, cryptomining | Ollama: / ...
show more
API honeypot | LLMjacking (Ollama) | 88 HTTP, 37s | tactics: outbound scan, cryptomining | Ollama: /api/tags,/api/show,/v1/models,/api/generate,/v1/chat/completions
show less
Hacking
Web App Attack
๐ฏ๐ต
Execoop
2026-05-12 11:40:46
(4 months ago)
API honeypot | LLMjacking (Ollama) | 7 HTTP, 2s | tactics: outbound scan | Ollama: /api/tags,/api/sh ...
show more
API honeypot | LLMjacking (Ollama) | 7 HTTP, 2s | tactics: outbound scan | Ollama: /api/tags,/api/show,/v1/models
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-08 15:37:33
(5 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-06 22:01:29
(5 months ago)
Auto-ban: 557 malicious requests on 2026-05-05 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 557 malicious requests on 2026-05-05 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
e.fierstra
2026-05-06 04:35:55
(5 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-05-06 00:20:04
(5 months ago)
Reported by internal abuse tracking
DDoS Attack
Web App Attack
๐บ๐ธ
avgsmoe
2026-05-05 20:59:10
(5 months ago)
CROWDSEC offender. Observed 86 times.
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
rh24
2026-05-05 20:22:33
(5 months ago)
(mod_security) mod_security triggered on hostname [redacted] 5.255.103.188 (NL/Netherlands/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-05-05 16:35:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.103.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.103.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 05 12:35:36.537808 2026] [security2:error] [pid 9263:tid 9376] [client 5.255.103.188:53512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.coldfusiondoctor.com"] [uri "/.git/config"] [unique_id "afocWEbOXjy7leuSibBkiAAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-05-04 23:11:07
(5 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-04 22:15:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.103.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.103.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 18:14:54.921420 2026] [security2:error] [pid 13725:tid 13725] [client 5.255.103.188:48822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.justicehoward.com"] [uri "/.git/config"] [unique_id "afkaXvB70VODEjuusBg13wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-04 01:16:14
(5 months ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-03 18:19:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.103.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.103.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 14:19:48.391640 2026] [security2:error] [pid 14332:tid 14340] [client 5.255.103.188:52860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "api.neotienda.com"] [uri "/.env_sample"] [unique_id "afeRxLP2fVLXJekhRhcJgQAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-05-03 12:37:39
(5 months ago)
101 requests with url.path *.git/*
Brute-Force
Bad Web Bot