๐ฌ๐ง
PeravixGroup
2026-05-23 01:20:10
(1 week ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
๐ฌ๐ง
PeravixGroup
2026-05-22 11:30:17
(1 week ago)
Honeypot detection: Elasticsearch unauthorized access / data leak attempt on port 9200. Severity: ME ...
show more
Honeypot detection: Elasticsearch unauthorized access / data leak attempt on port 9200. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐บ๐ธ
ShadowWhisperer
2026-05-08 08:11:08
(3 weeks ago)
DOCKER port scan / probe. GET /secrets
Port Scan
๐ฌ๐ง
PeravixGroup
2026-05-07 00:09:33
(4 weeks ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ฌ๐ง
PeravixGroup
2026-05-06 19:09:04
(4 weeks ago)
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity ...
show more
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity: CRITICAL. Aaran.cloud
show less
Hacking
Exploited Host
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
mnsf
2026-02-15 23:05:45
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2026-02-15 03:43:29
(3 months ago)
Blocking for trying to access an exploit file: /backend/.env
Hacking
๐ซ๐ท
dynamix
2026-02-14 22:18:51
(3 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-02-14 22:05:28
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ฉ๐ช
ut-addicted.com
2025-12-30 07:37:40
(5 months ago)
\[Tue Dec 30 08:37:36.723635 2025\] \[:error\] \[pid 4228:tid 140546160981760\] \[client 209.50.162. ...
show more
\[Tue Dec 30 08:37:36.723635 2025\] \[:error\] \[pid 4228:tid 140546160981760\] \[client 209.50.162.248:18633\] \[client 209.50.162.248\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 10\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "www.ut-addicted.com"\] \[uri "/.svn/wc.db"\] \[unique_id "aVOBQPOLLtDgSwrDN69ViwAAAMA"\]
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 09:12:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 04:12:46.111993 2025] [security2:error] [pid 4699:tid 4699] [client 209.50.162.248:55635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heinzmail.com"] [uri "/.svn/wc.db"] [unique_id "aVJGDnIaANL8iiIbsa6jcgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 06:30:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:29:56.277994 2025] [security2:error] [pid 7352:tid 7352] [client 209.50.162.248:41339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehiddengemmalta.com"] [uri "/.env"] [unique_id "aVIf5IFpITq6gfpDglfl3wAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:54:54
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:54:48.800632 2025] [security2:error] [pid 19343:tid 19343] [client 209.50.162.248:27413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdhcreations.com"] [uri "/.env"] [unique_id "aVIXqKTh8dqZUjQbci60FQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:22:36
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.162.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.162.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:22:32.128315 2025] [security2:error] [pid 8729:tid 8729] [client 209.50.162.248:33735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rkstewart.com"] [uri "/.env"] [unique_id "aVIQGCJPdI-Hj1XZjcMJlwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack