๐ท๐ธ
Scan
2026-07-31 01:43:10
(1 day ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
๐ฏ๐ต
demonsword
2026-07-05 13:50:19
(3 weeks ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: cp.cloudflare.com:80
show less
Open Proxy
Port Scan
๐ฆ๐น
urnilxfgbez
2026-06-03 22:45:00
(1 month ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
๐บ๐ธ
LSPCCU
2026-06-03 10:19:52
(1 month ago)
TSEC Honeypot Network report. Threat score: 100/100. Categories: Port Scan, Hacking, Brute-Force, We ...
show more
TSEC Honeypot Network report. Threat score: 100/100. Categories: Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: ssh-telnet, cowrie. Context: 20.
show less
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-06-03 07:00:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 20.109.38.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.109.38.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 03:00:07.577797 2026] [security2:error] [pid 13704:tid 13704] [client 20.109.38.226:63624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.13"] [uri "/.git/HEAD"] [unique_id "ah_Q93er-Xkyv9RfDa3lVAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Eric
2026-06-03 06:49:20
(1 month ago)
[Wed Jun 03 06:49:17.679210 2026] [security2:error] [pid 2157075:tid 2157075] [client 20.109.38.226: ...
show more
[Wed Jun 03 06:49:17.679210 2026] [security2:error] [pid 2157075:tid 2157075] [client 20.109.38.226:63302] [client 20.109.38.226] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.git/config"] [unique_id "ah_ObdKnv0NBzFk4RWzHWgAAABA"]
[Wed Jun 03 06:49:17.679706 2026] [security2:error] [pid 2157075:tid 2157075] [client 20.109.38.226:63302] [client 20.109.38.226] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.con
...
show less
Hacking
Web App Attack
๐ฉ๐ช
iNetWorker
2026-06-03 06:43:47
(1 month ago)
trying to access non-authorized port
Port Scan
๐บ๐ธ
SSP
2026-06-03 06:30:01
(1 month ago)
Automatic report from iptables firewall - detected malicious activity
DDoS Attack
Brute-Force
SSH
Web App Attack
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-03 06:29:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 20.109.38.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.109.38.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:29:08.694127 2026] [security2:error] [pid 31621:tid 31621] [client 20.109.38.226:63654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.56"] [uri "/.git/HEAD"] [unique_id "ah_JtJqctEnzc6HaFgHTRwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 06:00:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 20.109.38.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.109.38.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:00:27.407131 2026] [security2:error] [pid 8803:tid 8803] [client 20.109.38.226:63003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.30"] [uri "/.git/HEAD"] [unique_id "ah_C-3Gafl5hBovOPp-DtgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
soverin
2026-06-03 05:48:01
(1 month ago)
Network scan on port 80
Email Spam
๐บ๐ธ
TPI-Abuse
2026-06-03 05:38:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 20.109.38.226 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.109.38.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:38:37.555480 2026] [security2:error] [pid 13097:tid 13097] [client 20.109.38.226:57826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.152"] [uri "/.git/HEAD"] [unique_id "ah-93eXV12O6A3T0vVePBAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
Sawasdee
2026-06-03 04:42:11
(1 month ago)
Unwanted checking 80 or 443 port
...
Bad Web Bot
๐ง๐ท
SOC PR
2026-06-03 04:40:19
(1 month ago)
IPS: Web Server Exposed Git Repository Information Disclosure.
Hacking
๐ฉ๐ช
bsoft.de
2026-06-03 04:35:32
(1 month ago)
20.109.38.226 - - [03/Jun/2026:06:35:31 +0200] "GET /wp-config.php HTTP/1.1" 404 153 "-" "Mozilla/5. ...
show more
20.109.38.226 - - [03/Jun/2026:06:35:31 +0200] "GET /wp-config.php HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-"
show less
Bad Web Bot
Web App Attack