๐ฉ๐ช
Starburst SysOp Team
2026-09-21 10:28:09
(19 hours ago)
Found User-Agent associated with security scanner. Matched phrase "nmap" at REQUEST_HEADERS:User-Age ...
show more
Found User-Agent associated with security scanner. Matched phrase "nmap" at REQUEST_HEADERS:User-Agent. (913100-nue6-2)
show less
Hacking
Bad Web Bot
๐ฉ๐ช
sojan
2026-09-21 08:19:39
(21 hours ago)
207.175.29.85 - - [21/Sep/2026:10:19:10 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03X\xF5\xD ...
show more
207.175.29.85 - - [21/Sep/2026:10:19:10 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03X\xF5\xDE\x0E#\x85\xF3\xCA-\xE5\xFA\x07H\x84\xE7" 400 157 "-" "-"
207.175.29.85 - - [21/Sep/2026:10:19:33 +0200] "\x00\x1E\xA8)\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x07version\x04bind\x00\x00\x10\x00\x03" 400 157 "-" "-"
207.175.29.85 - - [21/Sep/2026:10:19:38 +0200] "\x03\x00\x00\x13\x0E\xE0\x00\x00\x00\x00\x00\x01\x00\x08\x00\x0B\x00\x00\x00" 400 157 "-" "-"
...
show less
Bad Web Bot
๐ณ๐ด
noteng.no
2026-09-21 07:37:52
(22 hours ago)
207.175.29.85 - - [21/Sep/2026:09:37:46 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xF7\xC6 ...
show more
207.175.29.85 - - [21/Sep/2026:09:37:46 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xF7\xC6\xE9Y` '\xD8\x7FVA1u\xF9`\x04ei\xCC\x09\xAB\x1D\xCA\xD3k\x94\xF3\x80T\xE8\x93\x19 \xD3\x97jl&\xBAn\x02\xFD\xFAMVq\x91\xD3\xD7#\xEB\xBE\xA5\xE7q\xC0\xF2k\x16\xCC\xFA\xE5\x17\xD5\xBF\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
207.175.29.85 - - [21/Sep/2026:09:37:51 +0200] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-"
207.175.29.85 - - [21/Sep/2026:09:37:51 +0200] "PG\x94D\x98\x04\x1E\xE7\xBF\xD0Rn\x93\x14\x87\xAF\xF8m\xDE\xCD\xDBI\xE4\x9CC*\xDA\xE5\xEF\x94\xDB\xAD\xDFb:\xC9" 400 150 "-" "-"
...
show less
Hacking
Web App Attack
๐ฎ๐ณ
nadnitin
2026-09-21 07:24:18
(22 hours ago)
Automated block via Nginx Police. Detected suspicious activity: MALICIOUS-HEX.
Web App Attack
๐ณ๐ฑ
knock
2026-09-21 07:02:42
(23 hours ago)
Knock-Knock honeypot brute-force: HTTP (1 total hits)
Web App Attack
๐ง๐ท
maviei
2026-09-21 06:48:50
(23 hours ago)
_ 207.175.29.85 - - [21/Sep/2026:03:47:52 -0300] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xD4\x ...
show more
_ 207.175.29.85 - - [21/Sep/2026:03:47:52 -0300] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xD4\xEC\x9D\xB4\xD9>\xCD?\xA4L\xFA{\x9B\xDF\x8A\x12\xAB\xE4\xDFL\xD3\x06\x972\x9F\x170^A\xC0\x92g \x5C\xC7k?\xE3AU\xAD\xA6\x962x\xCE\xAF(\xB4\x05\x0F\x96\xBCHo\xADd\xEDJ$\xEB\xBE\x1C1\xDD\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-" 0.232
_ 207.175.29.85 - - [21/Sep/2026:03:47:55 -0300] "\x86\xC5b\x1A>\xA2\x8C0\x09\xC0\x99~\x1D\xC4\xEC\x13\xEC\xD9HN\xE5\xC8\x1E\x9Cu\xD4D;~\xC1\xE2\xD2\xCC\xB9\xE2\x97\xF0y\xB7\xAB\x22\xC3\xD3\x11)\x09rW}" 400 150 "-" "-" 2.110
_ 207.175.29.85 - - [21/Sep/2026:03:47:55 -0300] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-" 3.058
_ 207.175.29.85 - - [21/Sep/2026:03:48:38 -0300] "\x00\x1E\xFE\xA1\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x07version\x04bind\x00\x00\x10\x00\x03" 40
...
show less
Bad Web Bot
๐ซ๐ฎ
6kilowatti
2026-09-21 06:31:13
(23 hours ago)
207.175.29.85 - - [21/Sep/2026:09:31:13 +0300] "\x16\x03\x00\x00i\x01\x00\x00e\x03\x03U\x1C\xA7\xE4r ...
show more
207.175.29.85 - - [21/Sep/2026:09:31:13 +0300] "\x16\x03\x00\x00i\x01\x00\x00e\x03\x03U\x1C\xA7\xE4random1random2random3random4\x00\x00\x0C\x00/\x00" 400 157 "-" "-"
...
show less
Web App Attack
๐ฉ๐ช
joharikop
2026-09-21 06:27:54
(23 hours ago)
Malformed HTTP request or known bad user agent detected by fail2ban on nginx reverse proxy
Bad Web Bot
๐ฉ๐ช
bescared
2026-09-21 06:04:29
(1 day ago)
F2B - Malicious activity detected. URL Probing. -c0423ad6-
Hacking
Web App Attack
๐บ๐ธ
gu-alvareza
2026-09-21 05:07:29
(1 day ago)
Java.Debug.Wire.Protocol.Insecure.Configuration
Hacking
๐บ๐ธ
cwytech
2026-09-21 05:04:42
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tactical-rmm-lockdown-high.
Hacking
๐จ๐ฆ
lakered
2026-09-21 04:50:11
(1 day ago)
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol ...
show more
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evidence: High-Criminality-Signature (p0f:*:64:0:*:mss*30,7:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.98), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:21479m)
show less
Port Scan
Exploited Host
๐ฉ๐ช
patrisei
2026-09-21 04:43:22
(1 day ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-probing
Port Scan
Web App Attack
๐บ๐ธ
crooze.net
2026-09-21 04:27:24
(1 day ago)
207.175.29.85 - - [21/Sep/2026:00:27:23 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x8F\xCC ...
show more
207.175.29.85 - - [21/Sep/2026:00:27:23 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x8F\xCC#\x9D'\xEF\xDD\xFEZ\x9B\xEC\x8Dx.\x83v\x19\x8C\x0ESv\xC6\x8C`\x09\x88\xBD\xDA\x0C\xA4\xCC\x80 GT\xC8 I\xD7D>2&\xFA\xC8)1\xF7\xCE\xDC\x98d\x9Fp'\x1E\xBAf\x13\x07\xC4\x94\xB9_v\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
...
show less
Hacking
Web App Attack
Anonymous
2026-09-21 03:50:22
(1 day ago)
PAD: ModSec_Scanner! detected
Bad Web Bot