Anonymous
2026-08-25 09:27:55
(1 week ago)
Scanner hitting /wp-includes/ID3/license.txt on () โ aaguard
Brute-Force
Port Scan
Anonymous
2026-08-24 09:13:02
(1 week ago)
Scanner hitting /wp-includes/ID3/license.txt on (GOOGL-2) โ aaguard
Brute-Force
Port Scan
๐ญ๐บ
miszterx.hu
2026-08-24 06:22:46
(1 week ago)
XORP (haproxy): 33x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 33x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-08-23 12:47:00
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: metrics.teddypot.website | URI: //wp-includes/ID3/license.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:37:09
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 34.182.208.8 (8.208.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.182.208.8 (8.208.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:37:03.936031 2026] [security2:error] [pid 10419:tid 10419] [client 34.182.208.8:61883] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bernsteinip.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aorpb3J_quZTUwqlG3J_ngAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Webhoster
2026-08-23 12:33:07
(1 week ago)
{"ClientAddr":"104.22.100.24:10407","ClientHost":"34.182.208.8","ClientPort":"10407","ClientUsername ...
show more
{"ClientAddr":"104.22.100.24:10407","ClientHost":"34.182.208.8","ClientPort":"10407","ClientUsername":"-","DownstreamContentSize":0,"DownstreamStatus":403,"Duration":15922653,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":15922653,"RequestAddr":"memo.timvdberg.dev","RequestContentSize":0,"RequestCount":176048,"RequestHost":"memo.timvdberg.dev","RequestMethod":"GET","RequestPath":"/wp-includes/ID3/license.txt","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"memo@file","StartLocal":"2026-08-23T12:33:07.621650789Z","StartUTC":"2026-08-23T12:33:07.621650789Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"34.182.208.8","request_X-Forwarded-For":"34.182.208.8","request_X-Real-Ip":"104.22.100.24","time":"2026-08-23T12:33:07Z"}
{"ClientAddr":"104.22.100.24:10407","ClientHost":"34.182.208.8","ClientPort":"10407","ClientUsername":"-",
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-23 12:32:27
(1 week ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ซ๐ฎ
YF
2026-08-23 12:31:03
(1 week ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-08-23 12:26:48
(1 week ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
iNetWorker
2026-08-23 12:22:18
(1 week ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-23 12:16:22
(1 week ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐ง๐ช
cmbplf
2026-08-23 12:04:58
(1 week ago)
6.082 post requests in 1 hour (1w5d17h)
Brute-Force
Bad Web Bot
๐ฉ๐ช
MSC IT for Business GmbH
2026-08-23 12:00:09
(1 week ago)
GASTO/CrowdSec: gasto/modsec-critical triggered (via crowdsec-agent, categories 15,21)
Hacking
Web App Attack
๐ฎ๐น
madaello
2026-08-23 11:53:34
(1 week ago)
34.182.208.8 - - [23/Aug/2026:13:53:31 +0200] "POST //xmlrpc.php HTTP/1.1" 200 646 "-" "Mozilla/5.0 ...
show more
34.182.208.8 - - [23/Aug/2026:13:53:31 +0200] "POST //xmlrpc.php HTTP/1.1" 200 646 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.182.208.8 - - [23/Aug/2026:13:53:32 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.182.208.8 - - [23/Aug/2026:13:53:33 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4522 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-08-23 11:53:18
(1 week ago)
34.182.208.8 - - [23/Aug/2026:13:51:58 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 " ...
show more
34.182.208.8 - - [23/Aug/2026:13:51:58 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "Washington" "38.89400" "-77.03650"
34.182.208.8 - - [23/Aug/2026:13:51:58 +0200] "GET //feed/ HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "Washington" "38.89400" "-77.03650"
34.182.208.8 - - [23/Aug/2026:13:51:58 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "Washington" "38.89400" "-77.03650"
34.182.208.8 - - [23/Aug/2026:13:51:58 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "Washington" "38.89400"
...
show less
Brute-Force
Bad Web Bot