🇧🇷
Peregrine
2026-08-30 03:11:29
(44 minutes ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: - 20.3.231.118 - - [28/Aug/2026:12:11:07 -0300] "GET /.gi ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: - 20.3.231.118 - - [28/Aug/2026:12:11:07 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
- 20.3.231.118 - - [28/Aug/2026:12:11:08 -0300] "GET /.git/config HTTP/1.1" 404 414
- 20.3.231.118 - - [28/Aug/2026:12:11:09 -0300] "GET /.git/logs/HEAD HTTP/1.1" 404 414
- 20.3.231.118 - - [28/Aug/2026:12:11:11 -0300] "GET /.git/refs/heads/master HTTP/1.1" 404 414
- 20.3.231.118 - - [28/Aug/2026:12:11:12 -0300] "GET /.git/refs/heads/main HTTP/1.1" 404 414
show less
Bad Web Bot
🇹🇷
SeczarSecureOps
2026-08-28 16:55:18
(1 day ago)
Auto-blocked by Seczar SecureOps — Sophos Horizontal Port Probe (20 events in 10min) at 2026-08-28 1 ...
show more
Auto-blocked by Seczar SecureOps — Sophos Horizontal Port Probe (20 events in 10min) at 2026-08-28 16:55
show less
Web App Attack
Anonymous
2026-08-28 16:33:22
(1 day ago)
unsolicited connect TCP dport 2078 (sport 23239)
Hacking
🇧🇷
Peregrine
2026-08-28 15:11:14
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: - 20.3.231.118 - - [28/Aug/2026:12:11:07 -0300] "GET /.gi ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: - 20.3.231.118 - - [28/Aug/2026:12:11:07 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
- 20.3.231.118 - - [28/Aug/2026:12:11:08 -0300] "GET /.git/config HTTP/1.1" 404 414
- 20.3.231.118 - - [28/Aug/2026:12:11:09 -0300] "GET /.git/logs/HEAD HTTP/1.1" 404 414
- 20.3.231.118 - - [28/Aug/2026:12:11:11 -0300] "GET /.git/refs/heads/master HTTP/1.1" 404 414
- 20.3.231.118 - - [28/Aug/2026:12:11:12 -0300] "GET /.git/refs/heads/main HTTP/1.1" 404 414
show less
Bad Web Bot
🇺🇸
Axel
2026-08-28 15:01:35
(1 day ago)
Blocked by UFW on LAXHH [443/tcp] | SPT: 23373 | TTL: 48 | LEN: 60 | TOS: 0x00 • Reported by: github ...
show more
Blocked by UFW on LAXHH [443/tcp] | SPT: 23373 | TTL: 48 | LEN: 60 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-08-28 14:08:43
(1 day ago)
denied traffic to a honeypot network. destination port 2078.
Port Scan
Hacking
🇮🇪
AutosOnShow
2026-08-28 13:53:04
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-08-28 13:52:40.456 |
Web App Attack
🇺🇸
MPL
2026-08-28 13:45:52
(1 day ago)
tcp port scan (10 or more attempts)
Port Scan
🇺🇸
TPI-Abuse
2026-08-28 13:31:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 20.3.231.118 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.3.231.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:31:49.662222 2026] [security2:error] [pid 26732:tid 26732] [client 20.3.231.118:23393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.100"] [uri "/.git/HEAD"] [unique_id "apGNxYCaeujJMYJE2P-fCgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 13:00:24
(1 day ago)
Drop from IP address 20.3.231.118 to tcp-port 443
Port Scan
🇺🇸
TPI-Abuse
2026-08-28 12:47:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 20.3.231.118 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.3.231.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:47:41.161549 2026] [security2:error] [pid 23617:tid 23617] [client 20.3.231.118:23534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.116"] [uri "/.git/HEAD"] [unique_id "apGDbQ-UDwIJf0CtI_1YKwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
lakered
2026-08-28 12:38:02
(1 day ago)
Detectors: [NGINX, SURICATA] | Reasons: Suricata: IDS security alert | Nginx Honeypot: Sensitive con ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Suricata: IDS security alert | Nginx Honeypot: Sensitive configuration file search | Evidence: High-Criminality-Signature (p0f:*:64:0:*:mss*44,10:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.89), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:IPIP or SIT, Uptime:31459m)
show less
Hacking
Web App Attack
🇯🇵
SentinalX by uzumaru
2026-08-19 04:31:35
(1 week ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: speed.cloudflare.com:443
show less
Open Proxy
Port Scan
🇺🇸
Rayulcifer
2026-08-19 04:31:30
(1 week ago)
20.3.231.118 - - [18/Aug/2026:23:31:02 -0500] "GET http://cachefly.cachefly.net/200mb.test HTTP/1.1" ...
show more
20.3.231.118 - - [18/Aug/2026:23:31:02 -0500] "GET http://cachefly.cachefly.net/200mb.test HTTP/1.1" 403 363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
20.3.231.118 - - [18/Aug/2026:23:31:02 -0500] "GET http://ipv4.download.thinkbroadband.com/1MB.zip HTTP/1.1" 403 363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
20.3.231.118 - - [18/Aug/2026:23:31:03 -0500] "GET http://speedtest.tele2.net/1MB.zip HTTP/1.1" 403 363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
20.3.231.118 - - [18/Aug/2026:23:31:03 -0500] "CONNECT speed.cloudflare.com:443 HTTP/1.1" 403 344 "-" "-"
20.3.231.118 - - [18/Aug/2026:23:31:03 -0500] "CONNECT speed.hetzner.de:443 HTTP/1.1" 403 344 "-" "-"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH
Anonymous
2026-08-03 09:54:26
(3 weeks ago)
denied traffic to a non-approved destination port. destination port 2078.
Port Scan