🇺🇸
donarev419
2026-09-13 03:34:29
(1 hour ago)
Connection to port 443 with data transfer.
Data preview:
Port Scan
Hacking
🇪🇸
Gem
2026-09-11 22:10:53
(1 day ago)
Unauthorized web scan.
Web App Attack
🇫🇷
Stara
2026-09-10 11:43:34
(2 days ago)
Automated block by CSF/LFD - suspicious activity detected
Brute-Force
Web App Attack
🇳🇱
Eric
2026-09-10 11:37:12
(2 days ago)
[Thu Sep 10 11:37:06.574447 2026] [security2:error] [pid 1410593:tid 1410593] [client 213.209.159.14 ...
show more
[Thu Sep 10 11:37:06.574447 2026] [security2:error] [pid 1410593:tid 1410593] [client 213.209.159.144:55027] [client 213.209.159.144] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/ssl-vpn/login.esp"] [unique_id "aqKWYqdacCipMFhsEx95owAAAAc"]
[Thu Sep 10 11:37:09.508607 2026] [security2:error] [pid 1133990:tid 1133990] [client 213.209.159.144:55089] [client 213.209.159.144] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.con
...
show less
Hacking
Web App Attack
🇺🇸
gerensat
2026-09-09 15:59:34
(3 days ago)
2026-09-09 12:59:34 | / | [] | Python-urllib/3.13
Web App Attack
🇪🇸
librebit
2026-09-08 20:06:06
(4 days ago)
Brute force
Brute-Force
🇫🇷
service Informatique
2026-09-08 04:00:37
(5 days ago)
POST /ssl-vpn
Web App Attack
🇹🇼
tyetriiix
2026-09-07 11:36:54
(5 days ago)
Wazuh Alert Evidence: 213.209.159.144 - - [07/Sep/2026:11:36:51 +0000] "POST /ssl-vpn/login.esp HTTP ...
show more
Wazuh Alert Evidence: 213.209.159.144 - - [07/Sep/2026:11:36:51 +0000] "POST /ssl-vpn/login.esp HTTP/1.1" 405 166 "-" "Python-urllib/3.13" "-" Origin: "-" CORS_Header: "-" Sent_allow_origin: "-"
show less
Web App Attack
🇬🇧
myintarweb
2026-09-05 02:45:23
(1 week ago)
213.209.159.144 - - [05/Sep/2026:03:45:23 +0100] 443 "POST /ssl-vpn/login.esp HTTP/1.1" 405 6767 "-" ...
show more
213.209.159.144 - - [05/Sep/2026:03:45:23 +0100] 443 "POST /ssl-vpn/login.esp HTTP/1.1" 405 6767 "-" "Python-urllib/3.13"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-09-04 18:08:27
(1 week ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/rdg-local-lockdown-high.
Bad Web Bot
Web App Attack
🇬🇧
Shadymint
2026-09-04 16:28:01
(1 week ago)
url probing from IP marked as abusive
Web App Attack
🇮🇩
sockominfo
2026-09-04 11:00:53
(1 week ago)
Active Response: IP 213.209.159.144 Blocked via Firewall Drop, Suspicious user agent detected Python ...
show more
Active Response: IP 213.209.159.144 Blocked via Firewall Drop, Suspicious user agent detected Python-urllib/3.13. Threat Score: 4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 57%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
🇮🇩
sockominfo
2026-09-04 10:00:13
(1 week ago)
Active Response: IP 213.209.159.144 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). R ...
show more
Active Response: IP 213.209.159.144 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇮🇳
nadnitin
2026-09-02 07:25:48
(1 week ago)
Automated trigger via Nginx Police. Reason: IP-SCANNER. Trigger Log: 213.209.159.144 - - [02/Sep/202 ...
show more
Automated trigger via Nginx Police. Reason: IP-SCANNER. Trigger Log: 213.209.159.144 - - [02/Sep/2026:12:55:47 +0530] "POST /ssl-vpn/login.esp HTTP/1.1" 444 0 "-" "Python-urllib/3.13"
show less
Port Scan
Anonymous
2026-09-01 14:51:15
(1 week ago)
213.209.159.144 - visio.sliver85.eu - [01/Sep/2026:16:51:06 +0200] "POST /ssl-vpn/login.esp HTTP/1.1 ...
show more
213.209.159.144 - visio.sliver85.eu - [01/Sep/2026:16:51:06 +0200] "POST /ssl-vpn/login.esp HTTP/1.1" 444 "Python-urllib/3.13"
213.209.159.144 - visio.sliver85.eu - [01/Sep/2026:16:51:10 +0200] "POST /ssl-vpn/login.esp HTTP/1.1" 444 "Python-urllib/3.13"
213.209.159.144 - visio.sliver85.eu - [01/Sep/2026:16:51:15 +0200] "POST /ssl-vpn/login.esp HTTP/1.1" 444 "Python-urllib/3.13"
...
show less
Brute-Force
Web App Attack