๐ซ๐ฎ
anycast_ac
2026-10-02 21:19:22
(8 hours ago)
Blocked by UFW on legacypanel [23/tcp] | SPT: 30965 | TTL: 51 | LEN: 40 | TOS: 0x00 โข Reported by: F ...
show more
Blocked by UFW on legacypanel [23/tcp] | SPT: 30965 | TTL: 51 | LEN: 40 | TOS: 0x00 โข Reported by: FemboyHolding LTD
show less
Port Scan
IoT Targeted
๐บ๐ธ
TPI-Abuse
2026-10-01 15:30:55
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 124.29.226.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 124.29.226.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:30:50.334256 2026] [security2:error] [pid 5932:tid 5932] [client 124.29.226.102:48909] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||velmat.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "velmat.com"] [uri "/"] [unique_id "ar58qusVFcg4GKKYueNp4QAAAA4"], referer: https://businessdirectorylinks.website/dir/manual-seo-backlinks-224615
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RAP
2026-10-01 08:02:24
(1 day ago)
2026-10-01 08:02:24 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
๐ซ๐ฎ
Birdo
2026-09-30 08:28:57
(2 days ago)
[Honeypot Report] Attempted malware delivery following Telnet intrusion
An automated malware loader ...
show more
[Honeypot Report] Attempted malware delivery following Telnet intrusion
An automated malware loader brute-forced our emulated Telnet service, then obtained shell access and executed commands, and finally attempted to retrieve a remote payload. Credentials and request paths match DVR / IP camera (OEM default), GPON/ONT fibre terminal.
Observed: 2026-09-30 06:58 to 2026-09-30 08:28 UTC | 815 sessions | 12,887 events | Telnet (port 23)
Attack chain:
1. 805 credential attempts: admin/CenturyL1nk, administrator/1234, root/xc3511, cunmgadmin/cunmgadmin, admin/gpon (+35 more pairs)
2. Shell access obtained; 11 distinct commands executed: start ; enable ; config terminal
3. Payload retrieval attempted from: http://103.19.49.134:43122/i
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/124.29.226.102.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
Exploited Host
Hacking
IoT Targeted
Brute-Force
๐น๐ท
Domainhizmetleri.com
2026-09-29 21:13:59
(3 days ago)
Source: DH Hunter (Honeypot) | Reason: Telnet Login Attempt (23/tcp)
Port Scan
SSH
Anonymous
2026-09-29 04:42:46
(4 days ago)
Port Scanner
Port Scan
๐บ๐ธ
LSPCCU
2026-09-29 03:26:18
(4 days ago)
TSEC Honeypot Network report. Threat score: 98/100. Categories: Port Scan, Hacking, Brute-Force, Exp ...
show more
TSEC Honeypot Network report. Threat score: 98/100. Categories: Port Scan, Hacking, Brute-Force, Exploited Host, Web App Attack, SSH, IoT Targeted. Honeypot: cowrie. Context: 124.29.226.102 classified as malware delivery infrastructure dropping payloads on compromised hosts (high confidence).
show less
Port Scan
Hacking
Brute-Force
Exploited Host
Web App Attack
SSH
IoT Targeted
๐บ๐ธ
RAP
2026-09-28 12:15:24
(4 days ago)
2026-09-28 12:15:24 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
๐บ๐ธ
MPL
2026-09-27 12:45:11
(5 days ago)
tcp/80 (3 or more attempts)
Port Scan
๐บ๐ธ
RAP
2026-09-24 22:31:44
(1 week ago)
2026-09-24 22:31:44 UTC Unauthorized activity to TCP port 2323. Telnet
Port Scan
๐ณ๐ฑ
rmvanderspek
2026-09-24 13:55:00
(1 week ago)
Telnet Brute-force (IoT Botnet scan) detected.
Brute-Force
IoT Targeted
๐บ๐ธ
xmission.com
2026-09-24 00:00:14
(1 week ago)
Blocked by UFW (TCP on 23)
Source port: 30719
TTL: 45
Packet length: 40
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 23)
Source port: 30719
TTL: 45
Packet length: 40
TOS: 0x00
This report (for 124.29.226.102) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Hacking
Brute-Force
๐ณ๐ฑ
EGP Abuse Dept
2026-09-22 09:43:19
(1 week ago)
Unauthorized connection to Telnet port 23
Port Scan
Hacking
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-17 16:30:17
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-09-17 13:26:50
(2 weeks ago)
unsolicited connect TCP dport 23 (sport 30645)
Hacking