๐จ๐ญ
SOC [GOLINE SA]
2026-10-02 09:55:20
(1 week ago)
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ...
show more
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ET CINS Active Threat Intelligence Poor Reputation IP group 197 | SID: 2403496 | Severity: 2 | Category: Misc Attack === SOURCE === IP: 144.79.16.144 (IPv4) | Port: 61000 | Country: United States | ISP: APNIC-ERX-144-79-0-0 | rDNS: None === TARGET === Host: nextcloud.goline.ch | IP: 185.54.81.37 | Port: 10000 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-10-02 09:55:19 | Action: Blocked
show less
Exploited Host
Hacking
๐จ๐ญ
SOC [GOLINE SA]
2026-10-02 06:50:35
(1 week ago)
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ...
show more
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ET CINS Active Threat Intelligence Poor Reputation IP group 197 | SID: 2403496 | Severity: 2 | Category: Misc Attack === SOURCE === IP: 144.79.16.144 (IPv4) | Port: 61000 | Country: United States | ISP: APNIC-ERX-144-79-0-0 | rDNS: None === TARGET === Host: nextcloud.goline.ch | IP: 185.54.81.37 | Port: 10000 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-10-02 06:50:34 | Action: Blocked
show less
Exploited Host
Hacking
๐จ๐ญ
SOC [GOLINE SA]
2026-10-02 02:17:44
(1 week ago)
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ...
show more
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ET CINS Active Threat Intelligence Poor Reputation IP group 197 | SID: 2403496 | Severity: 2 | Category: Misc Attack === SOURCE === IP: 144.79.16.144 (IPv4) | Port: 61000 | Country: United States | ISP: APNIC-ERX-144-79-0-0 | rDNS: None === TARGET === Host: wireguard.goline.ch | IP: 185.54.80.7 | Port: 5920 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-10-02 04:17:43 | Action: Blocked
show less
Exploited Host
Hacking
๐จ๐ญ
SOC [GOLINE SA]
2026-10-02 02:02:13
(1 week ago)
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Se ...
show more
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Severity: 1-2 | Category: Security Threat === SOURCE === IP: 144.79.16.144 (IPv4) | Port: N/A | Country: United States | ISP: APNIC-ERX-144-79-0-0 | rDNS: None === TARGET === Host: filecloud.goline.ch | IP: filecloud.goline.ch | Port: multiple | Protocol: TCP/UDP | App: N/A === RESPONSE === Time: 2026-10-02 04:02:12 | Action: Blocked
show less
Port Scan
Hacking
Bad Web Bot
๐ง๐ท
SSP
2026-10-01 13:30:06
(1 week ago)
Automatically generated from firewall_v2 logs on SID:VTSP4
Category: Port Scan
Occurrences: 28
Un ...
show more
Automatically generated from firewall_v2 logs on SID:VTSP4
Category: Port Scan
Occurrences: 28
Unique Ports: 28
Destination Ports:
6081, 5908, 5932, 5964, 9000, 6443, 5940, 5910, 6134, 7001, 5935, 5920, 5992, 5957, 5936, 6653, 5999, 5984, 6022, 5937, 6512, 5979, 5970, 5923, 5926, 5981, 5990, 5946
First Seen:
2026-10-01 12:30 UTC
Last Seen:
2026-10-01 13:05 UTC
show less
Port Scan
๐ฏ๐ต
Kinsei Engineering Inc.
2026-10-01 12:29:59
(1 week ago)
UFW:High-frequency access to unused ports
Port Scan
Anonymous
2026-10-01 06:09:20
(1 week ago)
Blocked by UFW [6003/tcp] | SPT: 61000 | TTL: 233 | LEN: 44 | TOS: 0x00 โข Reported by: github.com/se ...
show more
Blocked by UFW [6003/tcp] | SPT: 61000 | TTL: 233 | LEN: 44 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐จ๐ญ
Elysium Security
2026-09-30 19:46:21
(1 week ago)
Mass port scanning on a whole network
Port Scan
๐ฉ๐ช
KPS
2026-09-30 11:32:11
(1 week ago)
PortscanN
Port Scan
๐จ๐ญ
SOC [GOLINE SA]
2026-09-30 10:51:40
(1 week ago)
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ...
show more
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ET CINS Active Threat Intelligence Poor Reputation IP group 197 | SID: 2403496 | Severity: 2 | Category: Misc Attack === SOURCE === IP: 144.79.16.144 (IPv4) | Port: 61000 | Country: United States | ISP: APNIC-ERX-144-79-0-0 | rDNS: None === TARGET === Host: nextcloud.goline.ch | IP: 185.54.81.37 | Port: 10000 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-09-30 10:51:39 | Action: Blocked
show less
Exploited Host
Hacking
๐จ๐ญ
SOC [GOLINE SA]
2026-09-30 10:28:18
(1 week ago)
IDS Alert: GOLINE LG Webmin probed from outside the admin networks === ATTACK === Signature: GOLINE ...
show more
IDS Alert: GOLINE LG Webmin probed from outside the admin networks === ATTACK === Signature: GOLINE LG Webmin probed from outside the admin networks | SID: 7203001 | Severity: 3 | Category: Attempted Information Leak === SOURCE === IP: 144.79.16.144 (IPv4) | Port: 61000 | Country: United States | ISP: APNIC-ERX-144-79-0-0 | rDNS: None === TARGET === Host: lg.goline.ch | IP: 185.54.81.23 | Port: 10000 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-09-30 12:28:17 | Action: Blocked
show less
Port Scan
๐จ๐ญ
SOC [GOLINE SA]
2026-09-30 09:24:36
(1 week ago)
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ...
show more
IDS Alert: ET CINS Active Threat Intelligence Poor Reputation IP group 197 === ATTACK === Signature: ET CINS Active Threat Intelligence Poor Reputation IP group 197 | SID: 2403496 | Severity: 2 | Category: Misc Attack === SOURCE === IP: 144.79.16.144 (IPv4) | Port: 61000 | Country: United States | ISP: APNIC-ERX-144-79-0-0 | rDNS: None === TARGET === Host: insightvm.goline.ch | IP: 185.54.80.24 | Port: 6061 | Protocol: TCP | App: N/A === RESPONSE === Time: 2026-09-30 11:24:35 | Action: Blocked
show less
Exploited Host
Hacking
๐ฌ๐ง
sandra361
2026-09-30 07:00:31
(1 week ago)
Port scan detected: 18 attempts across 2 ports (6134, 9000). | Evidence: REAPER_TARPIT: IN=enp1s0f0 ...
show more
Port scan detected: 18 attempts across 2 ports (6134, 9000). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=144.79.16.144 LEN=78 TOS=0x00 PREC=0x00 TTL=237 ID=54073 PROTO=TCP SPT=61000 DPT=9000 WINDOW=1200 RES=0x00 ACK PSH URGP=0
show less
Port Scan
๐บ๐ธ
krss.llc
2026-09-30 04:35:00
(1 week ago)
Repeat portscan: 5905,5912,5914,5915,5936
Port Scan
๐ฉ๐ช
psauxit
2026-09-29 14:08:12
(1 week ago)
Fail2Ban - UFW port probing on unauthorized port
Port Scan