๐ต๐ฑ
sefinek.net
2026-10-08 12:34:39
(1 day ago)
Honeypot hit: HTTP/1.1 request on 9443
GET /
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKi ...
show more
Honeypot hit: HTTP/1.1 request on 9443
GET /
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate; 9443 [2] TCP
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Hacking
Bad Web Bot
Anonymous
2026-10-08 11:54:31
(1 day ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH
Anonymous
2026-08-14 04:21:01
(1 month ago)
denied traffic to a honeypot network. destination port 8181.
Port Scan
Hacking
๐ฉ๐ช
Admins@FBN
2026-08-14 03:40:53
(1 month ago)
FW-PortScan: Traffic Blocked srcport=61002 dstport=9000
Port Scan
๐บ๐ธ
COMPLEX
2026-08-14 03:36:35
(1 month ago)
Unsolicited TCP traffic | Action: DROP | Port 8899
Brute-Force
๐ฎ๐ฉ
Incidents Response Neptus Team
2025-03-04 22:53:00
(1 year ago)
Report Abuse IP
DDoS Attack
Hacking
Bad Web Bot
Exploited Host
Web App Attack
๐ธ๐ฌ
pusathosting.com
2025-02-18 16:33:03
(1 year ago)
2ds22 bruteforce
Brute-Force
Web App Attack
๐ฎ๐ฉ
hermawan
2025-02-17 15:29:35
(1 year ago)
[Mon Feb 17 22:29:34.636431 2025] [security2:error] [pid 137998:tid 140245362267840] [client 167.71. ...
show more
[Mon Feb 17 22:29:34.636431 2025] [security2:error] [pid 137998:tid 140245362267840] [client 167.71.93.209:52154] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "120"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: rest_route found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /?rest_route=/wp/v2/users/ HTTP/1.1 Request URI RAW = /?rest_route=/wp/v2/users/ Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "Z7NV3snonnHv0lQIlj0dOwAAADs"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[138139] [BtgAMdDaTUE] [Z7NV3snonnHv0lQIlj0dOwAAADs] keep_alive=[0] [2025-02-17 22:29:34.636436] [R:Z7NV3snonnHv0lQIlj0dOwAAADs] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-02-17 10:09:25
(1 year ago)
[Mon Feb 17 17:09:24.856493 2025] [security2:error] [pid 685430:tid 140048548755136] [client 167.71. ...
show more
[Mon Feb 17 17:09:24.856493 2025] [security2:error] [pid 685430:tid 140048548755136] [client 167.71.93.209:49744] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "120"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: rest_route found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /?rest_route=/wp/v2/users/ HTTP/1.1 Request URI RAW = /?rest_route=/wp/v2/users/ Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "Z7MK1BSJ2oTSoWYfTt3nCAAAAl8"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[685519] [874CuPuSTXs] [Z7MK1BSJ2oTSoWYfTt3nCAAAAl8] keep_alive=[0] [2025-02-17 17:09:24.856497] [R:Z7MK1BSJ2oTSoWYfTt3nCAAAAl8] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Hacking
Web App Attack
๐บ๐ธ
ANTI SCANNER
2025-01-30 18:08:59
(1 year ago)
Scanner : /admin/filemanager/dialog.php
Web Spam
๐ฎ๐น
Rosh
2025-01-30 10:45:29
(1 year ago)
[01/30/25 11:45:29] 1 attack: /filemanager/dialog.php (severity 5);
Web App Attack
๐ฌ๐ง
Bytemark
2025-01-21 21:37:04
(1 year ago)
167.71.93.209 - - [21/Jan/2025:21:37:03 +0000] "GET / HTTP/1.1" 200 23237 "-" "python-requests/2.32. ...
show more
167.71.93.209 - - [21/Jan/2025:21:37:03 +0000] "GET / HTTP/1.1" 200 23237 "-" "python-requests/2.32.3"
show less
Brute-Force
Web App Attack
๐บ๐ธ
snappic
2025-01-21 19:36:53
(1 year ago)
Scraping user agent [GET /] [python-requests/2.32.3]
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-17 13:55:03
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 167.71.93.209 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.71.93.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 17 08:54:57.188140 2025] [security2:error] [pid 17280:tid 17280] [client 167.71.93.209:58505] [client 167.71.93.209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.weddingmusicguitar.benshermanguitar.com"] [uri "/.env"] [unique_id "Z4phMazg9UlA8mwNzbwKVgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-01-17 13:38:41
(1 year ago)
399 requests to *.alfa
Brute-Force
Bad Web Bot