๐จ๐ณ
ThreatBook.io
2025-08-19 00:14:04
(1 year ago)
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/54.188.31.149
2025-08-1 ...
show more
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/54.188.31.149
2025-08-18 03:07:12 /
2025-08-18 04:14:19 /
2025-08-18 02:26:39 /
2025-08-18 03:47:35 /win.js
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-08-18 00:09:32
(1 year ago)
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/54.188.31.149
2025-08-1 ...
show more
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/54.188.31.149
2025-08-17 01:07:58 /batch.js
2025-08-17 01:07:58 /s/93e76fc25ea48c08d8b778e53d52d025-CDN/u06618/816001/1dlckms/0a0608319aa1d1e0e49d7c231957de49/_/download/contextbatch/js/_super/batch.js
2025-08-17 01:07:58 /secure/AboutPage.jspa/secure/AboutPage.js
2025-08-17 01:07:58 /secure/AboutPage.js
2025-08-17 00:17:09 /
2025-08-17 01:07:58 /osd.js
2025-08-17 01:07:58 /rest/api/1.0/shortcuts/816001/5445fc3a2eaf2d27d206b3310de52a0d/shortcuts.js
2025-08-17 01:07:46 /
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-08-16 23:55:33
(1 year ago)
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/54.188.31.149
2025-08-1 ...
show more
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/54.188.31.149
2025-08-16 03:35:58 /win.js
2025-08-16 03:28:57 /static/js/qrcode.min.js
2025-08-16 03:28:57 /static/js/md5.js
2025-08-16 03:35:47 /
2025-08-16 02:27:20 /
2025-08-16 03:28:47 /
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-08-16 00:29:23
(1 year ago)
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/54.188.31.149
2025-08-1 ...
show more
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/54.188.31.149
2025-08-15 12:27:24 /ext-3/adapter/ext/ext-base.js
2025-08-15 12:27:14 /
show less
Web App Attack
๐ฟ๐ฆ
Tokolosh Hunters
2025-08-14 23:24:15
(1 year ago)
AutoBlockWindow-Known bad useragent query-2025-08-14 23:24:14
Bad Web Bot
๐บ๐ธ
trevorleenc
2025-08-14 20:36:00
(1 year ago)
looking for jquery vuln(s)
Aug 14 16:25:17 - : 54.188.31.149 [page not found] jquery.cookie.js|ht ...
show more
looking for jquery vuln(s)
Aug 14 16:25:17 - : 54.188.31.149 [page not found] jquery.cookie.js|https://www.xxx.net/jquery.cookie.js||0
Aug 14 16:25:17 - : 54.188.31.149 [page not found] jquery_browser.js|https://www.xxx.net/jquery_browser.js||0
Aug 14 16:25:17 - : 54.188.31.149 [page not found] jquery.form.min.js|https://www.xxx.net/jquery.form.min.js||0
show less
Hacking
Web App Attack
๐บ๐ธ
RogueAutomata
2025-08-14 20:22:43
(1 year ago)
Detected malicious request: GET /cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js
Detectio ...
show more
Detected malicious request: GET /cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js
Detections triggered: Environment/config probe
show less
Web App Attack
๐ฉ๐ช
Hazzard
2025-08-14 19:55:01
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
Anonymous
2025-08-14 19:45:40
(1 year ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
BSG Webmaster
2025-08-14 18:52:46
(1 year ago)
Hacking Attempt using path //static.cloudflareinsights.com/beacon.min.js
Hacking
๐ฉ๐ช
expandmade.com
2025-08-14 18:46:19
(1 year ago)
trolling for installation vulnerabilities [14/Aug/2025:18:46:19 "GET //---/wp-content/cache/autoptim ...
show more
trolling for installation vulnerabilities [14/Aug/2025:18:46:19 "GET //---/wp-content/cache/autoptimize/js/autoptimize_36eaf3cf820767d670ead7635708d807.js"]
show less
Web App Attack
๐ง๐ช
cmbplf
2025-08-14 18:00:55
(1 year ago)
2.203 requests from abuseipdb.com blacklisted IP (1mo2d25mfromnow)
Brute-Force
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2025-08-14 17:54:45
(1 year ago)
54.188.31.149 - - [14/Aug/2025:18:54:29 +0100] "GET //4x4response.uk/wp-content/themes/customizr/ass ...
show more
54.188.31.149 - - [14/Aug/2025:18:54:29 +0100] "GET //4x4response.uk/wp-content/themes/customizr/assets/front/js/tc-scripts.min.js HTTP/1.0" 301 4263 "-" "Links (2.1pre15; FreeBSD 5.3-RELEASE i386; 196x84)"
54.188.31.149 - - [14/Aug/2025:18:54:29 +0100] "GET //4x4response.uk/wp-content/themes/customizr/assets/front/js/libs/modernizr.min.js HTTP/1.0" 301 4267 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.80 Safari/537.36"
54.188.31.149 - - [14/Aug/2025:18:54:29 +0100] "GET //4x4response.uk/wp-includes/js/jquery/jquery-migrate.min.js HTTP/1.0" 301 4245 "-" "Mozilla/5.0 (Linux; Android 9; SM-N960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2025-08-14 17:22:02
(1 year ago)
[Thu Aug 14 10:42:48.915274 2025] [authz_core:error] [pid 542525:tid 140556034147904] [client 54.188 ...
show more
[Thu Aug 14 10:42:48.915274 2025] [authz_core:error] [pid 542525:tid 140556034147904] [client 54.188.31.149:58282] AH01630: client denied by server configuration: /var/www/horde/
[Thu Aug 14 11:12:20.260858 2025] [authz_core:error] [pid 542525:tid 140556294321728] [client 54.188.31.149:53784] AH01630: client denied by server configuration: /var/www/horde/
[Thu Aug 14 11:22:02.166225 2025] [authz_core:error] [pid 541807:tid 140556008969792] [client 54.188.31.149:45920] AH01630: client denied by server configuration: /var/www/horde/
...
show less
Bad Web Bot
๐ซ๐ฎ
Jordy
2025-08-14 16:55:38
(1 year ago)
14/Aug/2025:18:57:11.879254 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
14/Aug/2025:18:57:11.879254 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 54.188.31.149] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "familievandemaat.nl"] [uri "/"] [unique_id "aJ4VZ3lcK1G2aYM1c19q8QAAAAM"]
14/Aug/2025:18:57:11.879254 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 54.188.31.149] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 a
...
show less
Web App Attack