π¨π
Kepler-1649c
2026-08-26 22:05:15
(7 hours ago)
Detected Attack: HTPasswd.Access
Hacking
π©πͺ
mattk
2026-08-26 19:09:38
(10 hours ago)
port scan
Port Scan
π©πͺ
bescared
2026-08-26 18:36:20
(11 hours ago)
F2B - Malicious activity detected. Excessive port scans. -151302cd-
Port Scan
π©πͺ
www.fransveldman.world
2026-08-06 12:23:05
(2 weeks ago)
Fetched browser challenge page 10 times in <2h without solving. Likely bad bot.
Bad Web Bot
Anonymous
2026-08-01 00:56:26
(3 weeks ago)
2096/tcp (1 or more attempts)
Port Scan
π·πΈ
Scan
2026-08-01 00:08:29
(3 weeks ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
π¨π
ZdenΔk Svancar
2026-07-31 23:40:18
(3 weeks ago)
134.33.70.50 - - [31/Jul/2026:23:40:07 +0000] "GET /.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Macinto ...
show more
134.33.70.50 - - [31/Jul/2026:23:40:07 +0000] "GET /.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
134.33.70.50 - - [31/Jul/2026:23:40:15 +0000] "GET /wp-config.php HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
...
show less
Port Scan
Bad Web Bot
Web App Attack
π©πͺ
centurion
2026-07-31 23:12:54
(3 weeks ago)
Blocked by UFW on ns02 [2087/tcp] Source port: 31753 TTL: 38 Packet length: 60 TOS: 0x00 This repor ...
show more
Blocked by UFW on ns02 [2087/tcp] Source port: 31753 TTL: 38 Packet length: 60 TOS: 0x00 This report was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
rellim.com
2026-07-31 22:50:43
(3 weeks ago)
Jul 31 15:50:42 alice kernel: HACK IN=enp3s0 OUT=enp1s0f1 MAC=68:05:ca:2e:ce:bc:00:24:dc:78:a0:01:08 ...
show more
Jul 31 15:50:42 alice kernel: HACK IN=enp3s0 OUT=enp1s0f1 MAC=68:05:ca:2e:ce:bc:00:24:dc:78:a0:01:08:00 SRC=134.33.70.50 DST=204.17.205.254 LEN=60 TOS=0x00 PREC=0x00 TTL=48 ID=47452 DF PROTO=TCP SPT=31122 DPT=2096 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 31 15:50:42 alice kernel: HACK IN=enp3s0 OUT=enp1s0f1 MAC=68:05:ca:2e:ce:bc:00:24:dc:78:a0:01:08:00 SRC=134.33.70.50 DST=204.17.205.254 LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=36264 DF PROTO=TCP SPT=30641 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 31 15:50:42 alice kernel: HACK IN=enp3s0 OUT=enp1s0f1 MAC=68:05:ca:2e:ce:bc:00:24:dc:78:a0:01:08:00 SRC=134.33.70.50 DST=204.17.205.254 LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=58030 DF PROTO=TCP SPT=29916 DPT=2082 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
Port Scan
π¬π§
wiredalter
2026-07-31 22:46:54
(3 weeks ago)
Blocked by fail2ban on gVPS [2086/tcp]
Source Port: 30815
TTL: 49
Packet Length: 60
TOS: 0x00
Analy ...
show more
Blocked by fail2ban on gVPS [2086/tcp]
Source Port: 30815
TTL: 49
Packet Length: 60
TOS: 0x00
Analyzed by https://ip.wiredalter.com
show less
Brute-Force
SSH
πΊπΈ
RAP
2026-07-31 22:02:34
(3 weeks ago)
2026-07-31 22:02:34 UTC Unauthorized activity to TCP port 8080. Web App
Port Scan
Web App Attack
π§π·
chronos
2026-07-31 22:02:00
(3 weeks ago)
Web traffic. Possible probing or exploitation attempts. | Port: 80 | Proto: TCP | Location: United S ...
show more
Web traffic. Possible probing or exploitation attempts. | Port: 80 | Proto: TCP | Location: United States, Phoenix
show less
Brute-Force
Hacking
Bad Web Bot
π©πͺ
Hary74656
2026-07-31 21:55:28
(3 weeks ago)
[Fri Jul 31 23:55:18.415738 2026] [security2:error] [pid 257059:tid 257117] [client 134.33.70.50:309 ...
show more
[Fri Jul 31 23:55:18.415738 2026] [security2:error] [pid 257059:tid 257117] [client 134.33.70.50:30932] [client 134.33.70.50] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "78.46.107.184"] [uri "/.git/HEAD"] [unique_id "am0Zxbat32k_3-ncgDc1SQAAAWI"]
[Fri Jul 31 23:55:18.983238 2026] [security2:error] [pid 257158:tid 257282] [client 134.33.70.50:30867] [client 134.33.70.50] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share
...
show less
Web App Attack
π©πͺ
MaxMeier
2026-07-31 20:27:43
(3 weeks ago)
134.33.70.50 - - [31/Jul/2026:22:26:41 +0200] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Wind ...
show more
134.33.70.50 - - [31/Jul/2026:22:26:41 +0200] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
134.33.70.50 - - [31/Jul/2026:22:26:42 +0200] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
134.33.70.50 - - [31/Jul/2026:22:26:45 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
134.33.70.50 - - [31/Jul/2026:22:26:46 +0200] "GET /.git/logs/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0"
134.33.70.50 - - [31/Jul/2026:22:26:47 +0200] "GET /.git/logs/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
134.33.70.50 - - [31/J
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-31 20:25:18
(3 weeks ago)
denied traffic to a honeypot network. destination port 8080.
Port Scan
Hacking