Anonymous
2026-06-17 05:16:46
(2 hours ago)
<jail> banned by fail2ban
Brute-Force
Web App Attack
๐ซ๐ท
bellovacorp
2026-06-17 04:02:24
(3 hours ago)
[CrowdSec/Noliae] noliae-threat-intel
Hacking
๐ง๐ท
Peregrine
2026-06-17 03:12:52
(4 hours ago)
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 154.26.133.2 - - [12/Jun/2026:17:38:24 -0300] "GET / ...
show more
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 154.26.133.2 - - [12/Jun/2026:17:38:24 -0300] "GET /.env HTTP/1.1" 404 414
- 154.26.133.2 - - [12/Jun/2026:17:38:25 -0300] "GET /.env.example HTTP/1.1" 404 414
- 154.26.133.2 - - [12/Jun/2026:17:38:26 -0300] "GET /.env.development HTTP/1.1" 404 414
show less
Bad Web Bot
๐ฉ๐ช
excill
2026-06-17 03:05:28
(4 hours ago)
Honeypot mesh observed 959 attack events in 24h โ cowrie/dionaea/heralding/suricata
Port Scan
Hacking
Brute-Force
SSH
Anonymous
2026-06-16 23:11:35
(8 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-06-16 19:17:03
(12 hours ago)
...
Web App Attack
๐ซ๐ฎ
mikethemagic
2026-06-16 15:54:29
(15 hours ago)
2026-06-16 12:38:53,890 fail2ban.actions [3985056]: NOTICE [ufw-scan] Ban 154.26.133.2
2026- ...
show more
2026-06-16 12:38:53,890 fail2ban.actions [3985056]: NOTICE [ufw-scan] Ban 154.26.133.2
2026-06-16 15:54:02,405 fail2ban.actions [3985056]: NOTICE [nginx-stella-scanner] Ban 154.26.133.2
...
show less
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-06-16 14:55:58
(16 hours ago)
Try to access /.env
Web App Attack
Anonymous
2026-06-16 14:51:00
(16 hours ago)
2026-06-16T14:51:00.112175+00:00 caddy caddy[63377]: {"level":"info","ts":1781621460.11201,"logger": ...
show more
2026-06-16T14:51:00.112175+00:00 caddy caddy[63377]: {"level":"info","ts":1781621460.11201,"logger":"http.log.access","msg":"handled request","request":{"remote_ip":"154.26.133.2","remote_port":"37956","client_ip":"154.26.133.2","proto":"HTTP/1.1","method":"GET","host":"142.132.232.19","uri":"/.env","headers":{"User-Agent":["Mozilla/5.0 (compatible)"],"Accept":["*/*"],"Accept-Encoding":["gzip, deflate"]}},"bytes_read":0,"user_id":"","duration":0.000072562,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://142.132.232.19/.env"],"Content-Type":[]}}
...
show less
Hacking
Web App Attack
๐ซ๐ฎ
oh.mg
2026-06-16 14:05:23
(17 hours ago)
[Tue Jun 16 16:05:21.052791 2026] [security2:error] [pid 3460682:tid 3460696] [client 154.26.133.2:5 ...
show more
[Tue Jun 16 16:05:21.052791 2026] [security2:error] [pid 3460682:tid 3460696] [client 154.26.133.2:51906] [client 154.26.133.2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "95.216.72.247"] [uri "/.env"] [unique_id "ajFYIWBoVlP8EcvMFJ5vwAAAAQw"]
[Tue Jun 16 16:05:22.732907 2026] [security2:error] [pid 3460682:tid 3460687] [client 154.26.133.2:51906] [client 154.26.133.2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anom
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
Erpelstolz
2026-06-16 13:30:42
(18 hours ago)
external host: 154.26.133.2 - - [16/Jun/2026:15:30:41 +0200] "GET /.git/HEAD HTTP/1.1" 403 261 "-" " ...
show more
external host: 154.26.133.2 - - [16/Jun/2026:15:30:41 +0200] "GET /.git/HEAD HTTP/1.1" 403 261 "-" "Mozilla/5.0 (compatible)" CF-Ray:- CF-IP:-
show less
Web App Attack
๐ซ๐ฎ
iamxorum
2026-06-16 12:35:00
(19 hours ago)
2026-06-16T12:35:00.188685+00:00 XRM-01 kernel: [HONEYPORT] IN=eth0 OUT= MAC=92:00:06:e6:da:95:d2:74 ...
show more
2026-06-16T12:35:00.188685+00:00 XRM-01 kernel: [HONEYPORT] IN=eth0 OUT= MAC=92:00:06:e6:da:95:d2:74:7f:6e:37:e3:08:00 SRC=154.26.133.2 DST=46.62.222.43 LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=36814 PROTO=TCP SPT=52702 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ฉ๐ช
mygcode.de
2026-06-16 08:56:09
(22 hours ago)
Scanning for Exploits
Bad Web Bot
๐ฉ๐ช
psauxit
2026-06-16 08:03:41
(23 hours ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking
๐ฉ๐ช
ghostwarriors
2026-06-16 07:20:32
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack