๐ฉ๐ช
LRob
2026-09-20 05:31:20
(3 hours ago)
Unauthorised hosting control panel login attempt | 2026-09-20 05:31 UTC
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2026-09-19 08:26:30
(1 day ago)
196.247.205.113 - - [19/Sep/2026:10:26:15 +0200] "POST /owa/auth.owa HTTP/1.1" 404 4674 "https://mai ...
show more
196.247.205.113 - - [19/Sep/2026:10:26:15 +0200] "POST /owa/auth.owa HTTP/1.1" 404 4674 "https://mail.rekittke-consulting.de/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2fmail.rekittke-consulting.de%2fowa%2f" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" 196.247.205.113 - - [19/Sep/2026:10:26:21 +0200] "POST /owa/auth.owa HTTP/1.1" 404 4673 "https://webmail.rekittke-consulting.de/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2fwebmail.rekittke-consulting.de%2fowa%2f" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" 196.247.205.113 - - [19/Sep/2026:10:26:29 +0200] "POST /owa/auth.owa HTTP/1.1" 404 4673 "https://exchange.rekittke-consulting.de/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2fcorreo.rekittke-consulting.de%2fowa%2f" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36"
show less
Brute-Force
Anonymous
2026-09-18 05:00:17
(2 days ago)
BruteForce IMAP/POP3/SMTP
Brute-Force
๐ซ๐ท
EvoX
2026-09-16 21:13:40
(3 days ago)
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Incoming HTTP request (dst port 81/tcp, src port 59106) against a pa ...
show more
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Incoming HTTP request (dst port 81/tcp, src port 59106) against a passive decoy web service with no legitimate content. Consistent with automated web scanning/exploitation attempts.
show less
Hacking
Bad Web Bot
๐ฉ๐ช
Jochen Pretli
2026-09-16 12:00:04
(3 days ago)
connection to honeypot
Email Spam
Port Scan
๐ต๐ฑ
Budyn
2026-09-14 10:05:36
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: auth.teddypot.cloud | URI: /storage/app/.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐จ๐ฟ
ddw
2026-09-14 09:56:18
(5 days ago)
Access Violation Attempts - Multiple 403 Forbidden responses.
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Teufel100
2026-09-10 10:38:13
(1 week ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
๐ซ๐ท
LRob
2026-09-10 05:37:44
(1 week ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /admin/.env | 2026-09-10 05:37 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
Reinhard
2026-09-08 09:28:39
(1 week ago)
Parameter or path manipulation, hacking. /.env.staging
Hacking
๐ต๐ฑ
Budyn
2026-09-07 23:19:31
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: portal.dont-eat-the-pudding.xyz | URI: /.env.staging | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-16 10:00:53
(1 month ago)
Zimbra: Login failures from malicious IP: 196.247.205.113. Threat Score: 6.2/10 (MEDIUM). Confidence ...
show more
Zimbra: Login failures from malicious IP: 196.247.205.113. Threat Score: 6.2/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 75%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-16 09:00:09
(1 month ago)
Zimbra: Login failures from malicious IP: 196.247.205.113. Threat Score: 5.5/10 (MEDIUM). Reported b ...
show more
Zimbra: Login failures from malicious IP: 196.247.205.113. Threat Score: 5.5/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 17:18:39
(1 month ago)
(mod_security) mod_security (id:210410) triggered by 196.247.205.113 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210410) triggered by 196.247.205.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:18:35.392239 2026] [security2:error] [pid 3321563:tid 3321576] [client 196.247.205.113:33814] ModSecurity: Access denied with code 403 (phase 2). Found 2 byte(s) in ARGS:f outside range: 1-255. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "95"] [id "210410"] [rev "4"] [msg "COMODO WAF: Invalid character in request||uoexpanse.com|F|3"] [data "ARGS:f=14\\x00AND 1=EXTRACTVALUE(1, CONCAT(0x7e21,(\\x00SELECT VERSION()),0x217e))--"] [severity "ERROR"] [tag "CWAF"] [tag "Protocol"] [hostname "uoexpanse.com"] [uri "/forums/viewtopic.php"] [unique_id "amzY6-4sAMfn4-DjEzW4qQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
legrx
2026-07-31 16:34:54
(1 month ago)
Fetched browser challenge page 18 times in <2h without solving. Likely bad bot.
Bad Web Bot