๐น๐ท
trakyabirlik
2026-10-11 01:42:45
(3 hours ago)
Auto-blocked by Seczar SecureOps โ High-Risk Port Probe (admin-managed entries) โ SSH (6 events in 5 ...
show more
Auto-blocked by Seczar SecureOps โ High-Risk Port Probe (admin-managed entries) โ SSH (6 events in 5min) at 2026-10-11 01:42
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-09 19:26:44
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 19:18:23
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 138.204.159.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 138.204.159.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 15:18:15.348234 2026] [security2:error] [pid 13548:tid 13548] [client 138.204.159.147:50858] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||koolcoastalnights.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "koolcoastalnights.com"] [uri "/"] [unique_id "asP395dRbQk9G53UIimSdAAAAA8"], referer: https://competitorbacklinks.space/dir/google-ranking-backlinks-115523
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-10-05 02:21:41
(6 days ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 18:19:37
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 138.204.159.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 138.204.159.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 14:19:31.860177 2026] [security2:error] [pid 22548:tid 22548] [client 138.204.159.147:57676] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kittysalterations.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kittysalterations.com"] [uri "/"] [unique_id "ar6kM7koHGI09Qk8ZA_nsQAAAAs"], referer: https://generatebacklinksinstantly.store/dir/relevant-domain-backlinks-114472
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:42:57
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 138.204.159.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 138.204.159.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:42:49.277780 2026] [security2:error] [pid 14110:tid 14110] [client 138.204.159.147:55691] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.pembrokefinance.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.pembrokefinance.com"] [uri "/403.shtml"] [unique_id "arzZmdsDMzytAlRKPMIlywAAAAA"], referer: https://seocompetitor.website/dir/link-outreach-services-160189
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 15:05:03
(1 week ago)
2026-09-29T17:05:02.682042+02:00 soli-gate postfix/smtpd[3178206]: NOQUEUE: reject: RCPT from unknow ...
show more
2026-09-29T17:05:02.682042+02:00 soli-gate postfix/smtpd[3178206]: NOQUEUE: reject: RCPT from unknown[138.204.159.147]: 554 5.7.25 Client host rejected: cannot find your hostname, [138.204.159.147]; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<[138.204.159.158]>
...
show less
Brute-Force
๐ฉ๐ช
Jochen Pretli
2026-09-27 00:49:35
(2 weeks ago)
connection to honeypot
Email Spam
Port Scan
๐ซ๐ฎ
mikkopal88
2026-09-26 20:45:34
(2 weeks ago)
TCP SYN port scan to Telnet 23-2323
Port Scan
IoT Targeted
๐บ๐ธ
MPL
2026-09-21 18:42:41
(2 weeks ago)
tcp ports: 22,23 (18 or more attempts)
Port Scan
๐บ๐ธ
NetVexor
2026-09-20 08:00:35
(2 weeks ago)
Attack source identified and submitted via NetVexor BGP Blackhole Network
Port Scan
Hacking
Brute-Force
๐ฉ๐ช
Tsumugi Kotobuki
2026-09-19 02:01:32
(3 weeks ago)
Port Scan on Honeypot | Ports: 23/Telnet | Proto: TCP(1) | Flags: all SYN | TTL: 36 | Len: 60B | Win ...
show more
Port Scan on Honeypot | Ports: 23/Telnet | Proto: TCP(1) | Flags: all SYN | TTL: 36 | Len: 60B | Win: 65535(1) | F2B/ufw-honeypot@2026-09-19T02:01:32Z
show less
Port Scan
Hacking
๐ซ๐ท
sthoyer.de
2026-09-16 19:50:09
(3 weeks ago)
Sep 16 21:50:07 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
Sep 16 21:50:07 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=138.204.159.147 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=11139 DF PROTO=TCP SPT=56602 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-16 18:50:34
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 138.204.159.147 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 138.204.159.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:50:26.349302 2026] [security2:error] [pid 23590:tid 23590] [client 138.204.159.147:47272] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||christmascardstropical.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "christmascardstropical.com"] [uri "/"] [unique_id "aqrk8nwumLL2lBF2FuimdwAAAA4"], referer: https://dadpchecker.online/dir/high-da-backlinks-39468
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
Sawasdee
2026-09-14 03:27:07
(3 weeks ago)
SSH break in attempt
...
SSH