Anonymous
2026-05-25 08:30:02
(1 week ago)
86.38.98.34 - - [25/May/2026:08:30:01 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1%20 ...
show more
86.38.98.34 - - [25/May/2026:08:30:01 +0000] "GET /bothole/stinkwell.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)),&start=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1" 307 825 "https://www.atari-forum.com/viewtopic.php?t=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)),&start=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO))," "-"
...
show less
SQL Injection
๐ฉ๐ช
HandyTreff.de
2026-05-18 18:12:35
(2 weeks ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -55.77 (Bad < -10 / Very Bad < -20 / ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -55.77 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: WhatsApp/2.23.20.0
show less
Web App Attack
Bad Web Bot
Anonymous
2026-05-16 11:29:22
(3 weeks ago)
SPROVFR WEBFORM SPAM 86.38.98.34 (86.38.98.34)
Web Spam
๐ช๐ธ
ofimare
2026-05-14 16:38:11
(3 weeks ago)
Brute-force
...
Brute-Force
Web App Attack
Bad Web Bot
๐ซ๐ฎ
mnazibo
2026-05-06 07:53:47
(1 month ago)
Reported IP: 86.38.98.34 WPLOGIN
DE/Germany/-
Connections: 10
Blocked: Permanent Block: [LF_CUSTOMTR ...
show more
Reported IP: 86.38.98.34 WPLOGIN
DE/Germany/-
Connections: 10
Blocked: Permanent Block: [LF_CUSTOMTRIGGER]
Logs: 86.38.98.34 - - [06/May/2026:10:53:32 +0300] "POST /wp-login.php HTTP/1.1" 404 47446 "https://my_domain/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:119.0) Gecko/20100101 Firefox/119.0"
86.38.98.34 - - [06/May/2026:10:53:33 +0300] "POST /wp-login.php HTTP/1.1" 404 47446 "https://my_domain/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
86.38.98.34 - - [06/May/2026:10:53:34 +0300] "POST /wp-login.php HTTP/1.1" 404 47446 "https://my_domain/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0"
86.38.98.34 - - [06/May/2026:10:53:35 +0300] "POST /wp-login.php HTTP/1.1" 404 47446 "https://my_domain/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
86.38.98.34 - - [06/May/2
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-10 06:01:41
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 86.38.98.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 86.38.98.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 02:01:36.543047 2026] [security2:error] [pid 1224222:tid 1224222] [client 86.38.98.34:38858] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.murphylumber.ca|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.murphylumber.ca"] [uri "/images/stories/themes.php"] [unique_id "adiSQKb6fVZ5sJlQwwdhBwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-04-09 22:35:55
(1 month ago)
326 requests with url.path */.well-known/acme-challenge/*.php
282 requests with url.path */.well-k ...
show more
326 requests with url.path */.well-known/acme-challenge/*.php
282 requests with url.path */.well-known/pki-validation/*.php
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-04-09 05:41:23
(1 month ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 09:39:01
(1 month ago)
(mod_security) mod_security (id:240000) triggered by 86.38.98.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 86.38.98.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 05:38:57.730966 2026] [security2:error] [pid 2719238:tid 2719238] [client 86.38.98.34:34096] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||petesplaza.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "petesplaza.com"] [uri "/images/stories/themes.php"] [unique_id "adYiMRW4YfxhsG0TRY7BogAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-04-07 01:13:56
(2 months ago)
Web vulnerability probing: /wp-content/plugins/ubh/
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 21:38:13
(2 months ago)
(mod_security) mod_security (id:240000) triggered by 86.38.98.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240000) triggered by 86.38.98.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 17:38:05.487670 2026] [security2:error] [pid 1070792:tid 1070792] [client 86.38.98.34:43078] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||lodge84.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "lodge84.org"] [uri "/images/stories/themes.php"] [unique_id "adQnvR0Dc4HlB55bNxBn1gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
TOCE
2026-04-06 15:33:02
(2 months ago)
7 hits seen on 2026-04-06, ports 5901 (VNC) on a honeypot from www.toce.ch
Brute-Force
๐ณ๐ฟ
Antinson
2026-04-06 09:21:09
(2 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
Anonymous
2026-04-04 07:23:07
(2 months ago)
BruteForce IMAP/POP3/SMTP
Brute-Force
Anonymous
2026-03-17 15:45:19
(2 months ago)
HTTP.URI.SQL.Injection
SQL Injection