๐ฉ๐ช
bescared
2026-09-16 12:35:24
(4 days ago)
F2B - Malicious activity detected. URL Probing. -c23856ef-
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 12:21:48
(4 days ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ธ๐ฌ
WMK965
2026-09-16 12:02:27
(4 days ago)
104.199.80.223 - - [16/Sep/2026:20:02:21 +0800] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xB4\x8 ...
show more
104.199.80.223 - - [16/Sep/2026:20:02:21 +0800] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xB4\x81\x185\xF5\xFE:G\xF3z\xBEz\x88\x1BwU\xC9\xF0\x1E\x10\xB2u\xFB\x1F\x97b5j\xF0\x9D\xA2\xED \x93T<H\x0CazpZ\x8B\xE3}<g\xA6\xE7\xE4M\x16\xCB\xC2,\x11\xC8gN\x036\xA3B\x97~\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 154 "-" "-" "-"
104.199.80.223 - - [16/Sep/2026:20:02:26 +0800] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 154 "-" "-" "-"
104.199.80.223 - - [16/Sep/2026:20:02:27 +0800] "T#\xC3|h\xAD\x91\x22,he\x0ET\x04\xC9m\x9C\x86\x88\xA3Y\xD1\x95\x1C\x8D\xF7\xB4K\x93\xE2\x96\xCE\xB2{\xAC\xB0\x95\x13\x07\x8F\x09/\xD0\xB1\xB39\xF3zj\xF2\x09\xF6\x917" 400 154 "-" "-" "-"
show less
Port Scan
Web App Attack
๐บ๐ธ
legionMCCXV
2026-09-16 11:41:00
(4 days ago)
Non-HTTP protocol data (e.g. MQTT/TLS handshake bytes) sent to HTTP(S) port.
Port Scan
Hacking
Anonymous
2026-09-16 10:48:18
(4 days ago)
104.199.80.223 - - [16/Sep/2026:12:48:17 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT ...
show more
104.199.80.223 - - [16/Sep/2026:12:48:17 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
104.199.80.223 - - [16/Sep/2026:12:48:18 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03E\xB2\xF4a\x01\xBD\xB1\x9B!\x8A@\xB4\x11\xB8X\x9D\xDC\xE8\x8E\x09\x8B<\x01\xDC\x11\x93ou\x9B\x90\x98\xB7 \xE7\xF39Z0\x10\x1E\xDA\xD9\x89\x18b\xCBw\xDB\x0E\xCAm\xC3l\xCB\xC45\x1A'u@\xE6\x1BD\xC1/\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
smithoo4
2026-09-16 10:47:37
(4 days ago)
104.199.80.223 - - [16/Sep/2026:06:47:34 -0400] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT ...
show more
104.199.80.223 - - [16/Sep/2026:06:47:34 -0400] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
104.199.80.223 - - [16/Sep/2026:06:47:36 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x89\x8F\xF7\xCC]\x16F\x90K\xA7ftf]\xAB=\x01Q\x15\xF3\x1Bi\xFB\xAF\x94}_7\xE7\x08\x02\x9A \xC10\xDB\xEB\xB2)\x93\x83\x1AZ\xAAa\x1D\x90V[\xE7\xFB\xF1m\xEFj\x0E\xAAz\xDA6Q\xF1\xAE0\xFC\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
...
show less
Port Scan
Bad Web Bot
๐บ๐ธ
kosada.com
2026-09-16 10:46:13
(4 days ago)
Repeated requests for suspicious nonexistent URLs, for example: / (HTTP/1.1 port 80, bogus vhost, us ...
show more
Repeated requests for suspicious nonexistent URLs, for example: / (HTTP/1.1 port 80, bogus vhost, user agent: "Mozilla/5.0 (compatible)")
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-16 10:23:52
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: tls_scann ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: tls_scanner. Observed by 1 sensor(s); 1 hits.
show less
Port Scan
Bad Web Bot
๐ฉ๐ช
Progetto1
2026-09-16 10:21:02
(4 days ago)
Detected via HAProxyScanner at 2026-09-16 10:21:02 UTC on destination port WEB (80/443). Repeated sc ...
show more
Detected via HAProxyScanner at 2026-09-16 10:21:02 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
donarev419
2026-09-16 09:41:48
(4 days ago)
Connection to port 80 with data transfer.
Data preview: GET / HTTP/1.1
Host: 198.23.188.201:80
Use ...
show more
Connection to port 80 with data transfer.
Data preview: GET / HTTP/1.1
Host: 198.23.188.201:80
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Apple
show less
Port Scan
Hacking
๐ญ๐ฐ
CyberFox
2026-09-16 09:13:05
(4 days ago)
80/tcp (1 or more attempts)
Port Scan
๐น๐ท
pashait
2026-09-16 09:02:46
(4 days ago)
Auto-blocked by Seczar SecureOps โ IPS Web Attack Signature (1 events in 5min) at 2026-09-16 09:02
Web App Attack
Bad Web Bot
๐ฉ๐ช
schuerholz
2026-09-16 09:00:05
(4 days ago)
Confirmed intrusion/exploit attempt detected and blocked by IPS (automated detection).
Hacking
Web App Attack
๐ฉ๐ช
zerodaysystemde
2026-09-16 08:40:17
(4 days ago)
Port (80 tcp) Scanner - WEB - HoneyPot
Port Scan
๐ฉ๐ช
Serpentex
2026-09-16 07:59:34
(4 days ago)
104.199.80.223 - - [16/Sep/2026:09:59:25 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xCAP\x ...
show more
104.199.80.223 - - [16/Sep/2026:09:59:25 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xCAP\xA3\xB0\x97r+>vMS\x06s\xEE{\x1A\xB4w\xC1\xAC\x93\x22p%\x8E'\xCB\xBC\xE5\xAB\x8F\xD9 \x8E\x8D\xFF\x11o\x8E\xE5\xE5j\x0ENv\x92\x12\xF2\x856\xC4\xD4@\x91\x1C\x95\xC1T]\xD8\xA43\x16\x9Eg\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
104.199.80.223 - - [16/Sep/2026:09:59:30 +0200] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-"
104.199.80.223 - - [16/Sep/2026:09:59:33 +0200] "X\x10a\xA7\xEF\xFC\x01\x89\xC6\x8F\xE2e\x00+\xAF\x0E[\xB3\x10\xA9\x8DC\x94\xAA\xE2\x0E\xA0H\x1D\xF6\x8F9\xC5\xF3G)\xDA\x1E\xC8\xBF\x0C[8\x96\xB0\xF9\x80\x16" 400 150 "-" "-"
...
show less
Bad Web Bot
Web App Attack