๐ฏ๐ต
Execoop
2026-05-16 08:33:46
(2 months ago)
API honeypot | LLMjacking (Ollama) | 71 HTTP, 50s | tactics: outbound scan, cryptomining | Ollama: / ...
show more
API honeypot | LLMjacking (Ollama) | 71 HTTP, 50s | tactics: outbound scan, cryptomining | Ollama: /api/tags,/api/show,/v1/models,/api/generate,/v1/chat/completions
show less
Hacking
Web App Attack
๐ฉ๐ช
heyzg
2026-05-15 04:42:16
(2 months ago)
API honeypot | LLMjacking (Ollama) | 46 HTTP, 39s | tactics: outbound scan, cryptomining | Ollama: / ...
show more
API honeypot | LLMjacking (Ollama) | 46 HTTP, 39s | tactics: outbound scan, cryptomining | Ollama: /api/tags,/api/show,/v1/models,/api/generate,/v1/chat/completions
show less
Hacking
Web App Attack
๐บ๐ธ
MuttMutt
2026-05-14 13:40:00
(2 months ago)
Massive automated vulnerability scan (over 11k requests in 10m) targeting multiple subdomains (www, ...
show more
Massive automated vulnerability scan (over 11k requests in 10m) targeting multiple subdomains (www, autoconfig, autodiscover, cpanel). Actor is using Python/aiohttp to probe for sensitive debugging information (/debug/vars, /debug/pprof/), system health status, and environment variables via CORS exploitation attempts (/api/cors/file:///app/.env). Originating from AME Hosting LLC (AS399244).
show less
Bad Web Bot
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-13 10:39:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 76.164.199.192 (192.199.164.76.bloom.host): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 76.164.199.192 (192.199.164.76.bloom.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 06:39:08.588691 2026] [security2:error] [pid 4536:tid 4536] [client 76.164.199.192:35774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.saldesica.com"] [uri "/.env.prod"] [unique_id "agRUzIKpJIxTENSUcMh2OgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-05-12 19:43:39
(2 months ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
๐ฉ๐ช
grassau.com
2026-05-12 00:24:28
(2 months ago)
*Port Scan* detected from 76.164.199.192 (US/United States/-/-/192.199.164.76.bloom.host).
Port Scan
๐ณ๐ฑ
Savvii
2026-05-11 16:33:20
(2 months ago)
20 attempts against mh-misbehave-ban on pea
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 07:16:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 76.164.199.192 (192.199.164.76.bloom.host): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 76.164.199.192 (192.199.164.76.bloom.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 03:16:48.984892 2026] [security2:error] [pid 5590:tid 5590] [client 76.164.199.192:36846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.gruponovak.com"] [uri "/.git/config"] [unique_id "agGCYNO6yY4EddngbHeIRAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-05-11 03:09:28
(2 months ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-11 02:39:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 76.164.199.192 (192.199.164.76.bloom.host): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 76.164.199.192 (192.199.164.76.bloom.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 22:39:18.755989 2026] [security2:error] [pid 15115:tid 15115] [client 76.164.199.192:42678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.hangrypandas.com"] [uri "/.git/config"] [unique_id "agFBVhbgxBIWjCeToGodFgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 01:43:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 76.164.199.192 (192.199.164.76.bloom.host): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 76.164.199.192 (192.199.164.76.bloom.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 21:43:05.037790 2026] [security2:error] [pid 17553:tid 17553] [client 76.164.199.192:43808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.jharsch.com"] [uri "/.svn/entries"] [unique_id "agE0KRD88arQXRnlNRogzwAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-11 00:47:48
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-09 20:38:17
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack