Anonymous
2026-09-03 14:17:48
(4 hours ago)
denied traffic to a non-approved destination port. destination port 2086.
Port Scan
Anonymous
2026-07-11 03:39:07
(1 month ago)
2026-07-11 05:39:04.709 [67977] no host name found for IP address 20.109.39.48
2026-07-11 05:39:04.9 ...
show more
2026-07-11 05:39:04.709 [67977] no host name found for IP address 20.109.39.48
2026-07-11 05:39:04.921 [67977] SMTP protocol error in "AUTH LOGIN" H=(ADMIN) [20.109.39.48]:15953 I=[217.197.86.168]:587 Ci=67977 AUTH command used when not advertised
2026-07-11 05:39:05.224 [67977] no MAIL in SMTP connection from (ADMIN) [20.109.39.48]:15953 I=[217.197.86.168]:587 Ci=67977 D=0.609s C=EHLO,AUTH,QUIT
...
show less
Email Spam
🇿🇦
maximonline.co.za
2026-07-11 03:10:03
(1 month ago)
Brute Force SMTP AUTH Attack
Brute-Force
🇺🇸
MPL
2026-06-22 18:49:10
(2 months ago)
tcp port scan (8 or more attempts)
Port Scan
🇺🇸
TPI-Abuse
2026-06-22 17:35:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 20.109.39.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.109.39.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 13:35:00.941638 2026] [security2:error] [pid 30273:tid 30273] [client 20.109.39.48:57172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.103"] [uri "/.git/config"] [unique_id "ajlyRBCWT4-mIYgZTrHHVAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
zwebvigil
2026-06-22 16:16:11
(2 months ago)
20.109.39.48 [22/Jun/2026:09:16:05 -0700] "GET /.git/HEAD HTTP/1.1" 401 381 "-" port=57030 "Mozilla ...
show more
20.109.39.48 [22/Jun/2026:09:16:05 -0700] "GET /.git/HEAD HTTP/1.1" 401 381 "-" port=57030 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0" "-" "-" "<ipaddr>" 1239
20.109.39.48 [22/Jun/2026:09:16:07 -0700] "GET /.git/config HTTP/1.1" 401 381 "-" port=57044 "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15" "-" "-" "<ipaddr>" 834
20.109.39.48 [22/Jun/2026:09:16:07 -0700] "GET /.git/logs/HEAD HTTP/1.1" 401 381 "-" port=57045 "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0" "-" "-" "<ipaddr>" 241
20.109.39.48 [22/Jun/2026:09:16:08 -0700] "GET /.git/refs/heads/master HTTP/1.1" 401 381 "-" port=57026 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "-" "-" "<ipaddr>" 404
20.109.39.48 [22/Jun/2026
show less
Web App Attack
Anonymous
2026-06-22 15:18:49
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
🇯🇵
demonsword
2026-05-11 17:55:44
(3 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: ptlogin.4399.com:443
show less
Open Proxy
Port Scan
🇺🇸
TPI-Abuse
2026-04-10 12:51:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 20.109.39.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.109.39.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 08:51:42.700176 2026] [security2:error] [pid 1638268:tid 1638268] [client 20.109.39.48:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.abdulhameeds.art"] [uri "/.git/config"] [unique_id "adjyXsIisrL2JaQpK008PQAAAAs"], referer: https://www.yahoo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-10 09:17:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 20.109.39.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.109.39.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 05:17:04.979047 2026] [security2:error] [pid 1466639:tid 1466639] [client 20.109.39.48:25537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "francesphilosophy.cygnetsilks.com"] [uri "/@fs/app/.git/config"] [unique_id "adjAEKLrbuuVwMNsU1K8ugAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
Agrohim
2026-04-09 03:24:56
(4 months ago)
Gate Inet blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
🇷🇺
Agrohim
2026-03-13 00:54:23
(5 months ago)
Gate Inet blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
🇵🇱
MatStef132
2026-03-01 10:55:20
(6 months ago)
2026-03-01T11:55:14.010201+01:00 pl2 sshd[515645]: Failed password for root from 20.109.39.48 port 7 ...
show more
2026-03-01T11:55:14.010201+01:00 pl2 sshd[515645]: Failed password for root from 20.109.39.48 port 7370 ssh2
2026-03-01T11:55:14.108016+01:00 pl2 sshd[517003]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=20.109.39.48 user=root
2026-03-01T11:55:16.623480+01:00 pl2 sshd[517003]: Failed password for root from 20.109.39.48 port 7622 ssh2
2026-03-01T11:55:18.379954+01:00 pl2 sshd[519284]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=20.109.39.48 user=root
2026-03-01T11:55:20.442474+01:00 pl2 sshd[519284]: Failed password for root from 20.109.39.48 port 7527 ssh2
...
show less
Brute-Force
SSH
🇵🇱
MatStef132
2026-03-01 10:34:56
(6 months ago)
2026-03-01T11:34:51.732899+01:00 pl2 sshd[3983584]: Failed password for root from 20.109.39.48 port ...
show more
2026-03-01T11:34:51.732899+01:00 pl2 sshd[3983584]: Failed password for root from 20.109.39.48 port 7660 ssh2
2026-03-01T11:34:52.105710+01:00 pl2 sshd[3985187]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=20.109.39.48 user=root
2026-03-01T11:34:53.862532+01:00 pl2 sshd[3985187]: Failed password for root from 20.109.39.48 port 7667 ssh2
2026-03-01T11:34:53.505695+01:00 pl2 sshd[3985189]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=20.109.39.48 user=root
2026-03-01T11:34:55.398997+01:00 pl2 sshd[3985189]: Failed password for root from 20.109.39.48 port 7616 ssh2
...
show less
Brute-Force
SSH
🇵🇱
MatStef132
2026-03-01 10:14:32
(6 months ago)
2026-03-01T11:14:28.813179+01:00 pl2 sshd[3261429]: Failed password for root from 20.109.39.48 port ...
show more
2026-03-01T11:14:28.813179+01:00 pl2 sshd[3261429]: Failed password for root from 20.109.39.48 port 7517 ssh2
2026-03-01T11:14:30.201032+01:00 pl2 sshd[3264351]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=20.109.39.48 user=root
2026-03-01T11:14:31.864114+01:00 pl2 sshd[3264351]: Failed password for root from 20.109.39.48 port 7498 ssh2
2026-03-01T11:14:30.550834+01:00 pl2 sshd[3264353]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=20.109.39.48 user=root
2026-03-01T11:14:32.213919+01:00 pl2 sshd[3264353]: Failed password for root from 20.109.39.48 port 7495 ssh2
...
show less
Brute-Force
SSH