๐บ๐ธ
JL41414141
2026-09-16 17:07:55
(23 hours ago)
147.93.129.14 - - [16/Sep/2026:17:07:54 +0000] "GET /ndp/adminlogin.php HTTP/1.1" 404 118 "-" "Mozil ...
show more
147.93.129.14 - - [16/Sep/2026:17:07:54 +0000] "GET /ndp/adminlogin.php HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0"
147.93.129.14 - - [16/Sep/2026:17:07:55 +0000] "GET /ndp/adminlogin.php HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0"
...
show less
Web Spam
๐ฏ๐ต
ZEROVOX
2026-09-16 12:11:44
(1 day ago)
CrowdSec: crowdsecurity/http-admin-interface-probing detected
Web App Attack
๐บ๐ธ
cwytech
2026-09-16 12:00:41
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tactical-rmm-lockdown-high.
Hacking
๐บ๐ธ
Starburst SysOp Team
2026-09-16 11:28:27
(1 day ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-iad5-2)
Hacking
Bad Web Bot
๐ฌ๐ง
sonot
2026-09-15 19:38:09
(1 day ago)
Blocked by UFW on tunneluk01 [3306/tcp] | SPT: 53808 | TTL: 49 | LEN: 60 | TOS: 0x00 โข Reported by: ...
show more
Blocked by UFW on tunneluk01 [3306/tcp] | SPT: 53808 | TTL: 49 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ธ๐ฌ
WMK965
2026-09-14 20:56:13
(2 days ago)
147.93.129.14 - - [15/Sep/2026:04:56:11 +0800] "GET /ns-api/v2/version HTTP/1.1" 444 0 "-" "Mozilla/ ...
show more
147.93.129.14 - - [15/Sep/2026:04:56:11 +0800] "GET /ns-api/v2/version HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0" "-"
147.93.129.14 - - [15/Sep/2026:04:56:11 +0800] "GET /ns-api/v2/version HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0" "-"
147.93.129.14 - - [15/Sep/2026:04:56:12 +0800] "GET /ndp/adminlogin.php HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0" "-"
show less
Port Scan
Web App Attack
๐จ๐ญ
m_vlasov
2026-09-14 20:02:10
(2 days ago)
SSH/Telnet honeypot: 0 login attempts, 0 sessions, 0 shell commands.
Hacking
๐ฉ๐ช
tinect
2026-09-14 19:34:37
(2 days ago)
This IP was detected by CrowdSec triggering tinect/http-sensitive-file-probe
Web App Attack
Anonymous
2026-09-14 19:05:43
(2 days ago)
[TCP/80] Unsolicited connection attempt on a port with no legitimate public service.
Port Scan
Hacking
๐ฉ๐ช
initsol
2026-09-14 18:45:21
(2 days ago)
[Mon Sep 14 20:45:13.011010 2026] [authz_core:error] [pid 3612770:tid 3612770] [client 147.93.129.14 ...
show more
[Mon Sep 14 20:45:13.011010 2026] [authz_core:error] [pid 3612770:tid 3612770] [client 147.93.129.14:37146] AH01630: client denied by server configuration: /var/www/ndp
[Mon Sep 14 20:45:17.419270 2026] [authz_core:error] [pid 3612768:tid 3612768] [client 147.93.129.14:37156] AH01630: client denied by server configuration: /var/www/LiCf
[Mon Sep 14 20:45:21.513393 2026] [authz_core:error] [pid 3624459:tid 3624459] [client 147.93.129.14:50728] AH01630: client denied by server configuration: /var/www/SiPbx
...
show less
Brute-Force
๐บ๐ธ
kuj
2026-09-14 18:08:25
(2 days ago)
2026-09-14T12:08:23.396923-06:00 derpamp-oci derper[95333]: 2026/09/14 12:08:23 http: TLS handshake ...
show more
2026-09-14T12:08:23.396923-06:00 derpamp-oci derper[95333]: 2026/09/14 12:08:23 http: TLS handshake error from 147.93.129.14:44034: acme/autocert: missing server name
2026-09-14T12:08:24.157800-06:00 derpamp-oci derper[95333]: 2026/09/14 12:08:24 http: TLS handshake error from 147.93.129.14:44036: acme/autocert: missing server name
2026-09-14T12:08:25.067862-06:00 derpamp-oci derper[95333]: 2026/09/14 12:08:25 http: TLS handshake error from 147.93.129.14:44046: acme/autocert: missing server name
...
show less
Port Scan
Brute-Force
๐ฉ๐ช
ecs.ge
2026-09-14 16:10:33
(3 days ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐ฎ๐ฑ
Ilop
2026-09-14 15:32:20
(3 days ago)
[v5-99] Firewall dropped 3 unsolicited packet(s) proto=tcp to port(s) 3306,80 from 147.93.129.14 โ W ...
show more
[v5-99] Firewall dropped 3 unsolicited packet(s) proto=tcp to port(s) 3306,80 from 147.93.129.14 โ WAN scan (automated sensor)
show less
Port Scan
๐ฉ๐ช
netclix.gr
2026-09-14 15:18:39
(3 days ago)
(c5_web_scan) Custom5 Aggressive Web Scan 147.93.129.14 (US/United States/vmi3570706.contaboserver.n ...
show more
(c5_web_scan) Custom5 Aggressive Web Scan 147.93.129.14 (US/United States/vmi3570706.contaboserver.net): 3 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: default:80 147.93.129.14 - - [14/Sep/2026:18:01:39 +0300] "GET /ndp/adminlogin.php HTTP/1.1" 404 402 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0"
default:80 147.93.129.14 - - [14/Sep/2026:18:01:42 +0300] "GET /LiCf/adminlogin.php HTTP/1.1" 404 402 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0"
default:80 147.93.129.14 - - [14/Sep/2026:18:01:44 +0300] "GET /SiPbx/adminlogin.php HTTP/1.1" 404 402 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0"
show less
Port Scan
๐ฉ๐ช
guldkage
2026-09-14 01:41:41
(3 days ago)
Unauthorized connection attempt detected from IP address 147.93.129.14 to port 3306 (ger-03) [M]
Brute-Force
Exploited Host