๐ฉ๐ช
Jochen Pretli
2026-10-08 15:07:03
(1 hour ago)
connection to honeypot
Email Spam
Port Scan
๐ฉ๐ช
onkeltom
2026-10-08 14:48:13
(2 hours ago)
Unauthorized connection attempts
Brute-Force
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 14:02:09
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.60.242.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 217.60.242.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:02:05.253664 2026] [security2:error] [pid 32590:tid 32590] [client 217.60.242.58:38386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.7"] [uri "/.env"] [unique_id "aseiXZl6JD6ewuwRBcmcugAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
lakered
2026-10-08 13:57:29
(2 hours ago)
Detectors: [CROWDSEC, NGINX] | Reasons: CrowdSec: Security alert | Nginx Honeypot: Sensitive configu ...
show more
Detectors: [CROWDSEC, NGINX] | Reasons: CrowdSec: Security alert | Nginx Honeypot: Sensitive configuration file search | Evidence: Trusted-P0F-Signature (*:64:0:*:mss*44,7:mss,sok,ts,nop,ws:df,id+:0), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:PPPoE, Uptime:3028m)
show less
Web App Attack
Hacking
๐บ๐ธ
Starburst SysOp Team
2026-10-08 13:56:42
(2 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-stl2-14)
Hacking
Bad Web Bot
๐ฉ๐ช
Progetto1
2026-10-08 13:54:01
(3 hours ago)
Detected via HAProxyScanner at 2026-10-08 13:54:01 UTC on destination port WEB (80/443). Repeated sc ...
show more
Detected via HAProxyScanner at 2026-10-08 13:54:01 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
Port Scan
Hacking
Brute-Force
๐จ๐ฟ
Prcek
2026-10-08 13:46:51
(3 hours ago)
PortScan:HOST=217.60.242.58,DPORTS=80
Port Scan
๐ฉ๐ช
Mirage F1
2026-10-08 13:44:00
(3 hours ago)
217.60.242.58 - - [08/Oct/2026:14:40:11 +0200] "GET /.env.save HTTP/1.1"
217.60.242.58 - - [08/Oct ...
show more
217.60.242.58 - - [08/Oct/2026:14:40:11 +0200] "GET /.env.save HTTP/1.1"
217.60.242.58 - - [08/Oct/2026:14:40:11 +0200] "GET /.env.swp HTTP/1.1"
217.60.242.58 - - [08/Oct/2026:14:40:11 +0200] "GET /api/.env HTTP/1.1"
217.60.242.58 - - [08/Oct/2026:14:40:11 +0200] "GET /app/.env HTTP/1.1"
217.60.242.58 - - [08/Oct/2026:14:40:12 +0200] "GET /backend/.env HTTP/1.1"
217.60.242.58 - - [08/Oct/2026:14:40:12 +0200] "GET /server/.env HTTP/1.1"
217.60.242.58 - - [08/Oct/2026:14:40:12 +0200] "GET /public/.env HTTP/1.1"
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 13:38:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.60.242.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 217.60.242.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:38:10.292022 2026] [security2:error] [pid 10331:tid 10331] [client 217.60.242.58:40218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.199"] [uri "/.env"] [unique_id "asecwiCokUSdsUqshcs3xwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
Domainhizmetleri.com
2026-10-08 13:33:31
(3 hours ago)
Source: DH Hunter (Honeypot) | Reason: HTTP Probe (80/tcp)
Web App Attack
๐ซ๐ท
Little Iguana
2026-10-08 13:32:06
(3 hours ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ง๐ท
Host One
2026-10-08 13:30:04
(3 hours ago)
T-Pot Honeypot alert: 145 malicious events (exploit_attempt, port_scan) detected.
Port Scan
Hacking
๐บ๐ธ
Rip
2026-10-08 13:23:06
(3 hours ago)
Automated reconnaissance against web infrastructure.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:22:09
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.60.242.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 217.60.242.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:22:03.313746 2026] [security2:error] [pid 2409:tid 2452] [client 217.60.242.58:38456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.24"] [uri "/.env"] [unique_id "aseY-8vM1dVv005GC42usQAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-10-08 13:20:00
(3 hours ago)
CrowdSec crowdsecurity/http-sensitive-files
Web App Attack