๐ท๐บ
webserfer
2026-10-08 17:57:05
(5 hours ago)
[f2b] honeypot [W1:1:?]
Port Scan
Hacking
๐บ๐ฆ
TawnyBalfour
2026-09-19 18:31:44
(2 weeks ago)
SMB honeypot. Target port: 445. Window: 2026-09-19 18:31 to 2026-09-19 18:31 UTC.
Port Scan
Anonymous
2026-08-25 09:27:52
(1 month ago)
Scanner hitting /.env on () โ aaguard
Brute-Force
Port Scan
Anonymous
2026-08-23 13:47:27
(1 month ago)
Scanner hitting /.env on () โ aaguard
Brute-Force
Port Scan
๐ณ๐ฑ
Cyber SOC
2026-08-18 08:04:46
(1 month ago)
Peaksys - 2026-08-18 09:01:02 UTC+01
Port Scan
Hacking
SQL Injection
Web App Attack
๐ณ๐ฑ
JCB
2026-08-12 13:15:00
(1 month ago)
217.64.126.24 - - [12/Aug/2026:07:06:24 +0300] "GET /wp-content/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 ...
show more
217.64.126.24 - - [12/Aug/2026:07:06:24 +0300] "GET /wp-content/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 10:36:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 217.64.126.24 (unassigned): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 217.64.126.24 (unassigned): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 06:36:13.876773 2026] [security2:error] [pid 25621:tid 25621] [client 217.64.126.24:63381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.71"] [uri "/.env"] [unique_id "anxMncOUh06medZcGP93CQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
knock
2026-08-12 10:34:17
(1 month ago)
Knock-Knock honeypot brute-force: proto8 (2 total hits)
Brute-Force
๐ซ๐ท
LRNP
2026-08-12 10:13:38
(1 month ago)
_:80 217.64.126.24 - - [12/Aug/2026:10:13:25 +0000] "GET /.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (M ...
show more
_:80 217.64.126.24 - - [12/Aug/2026:10:13:25 +0000] "GET /.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 10:03:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 217.64.126.24 (unassigned): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 217.64.126.24 (unassigned): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 06:03:26.794252 2026] [security2:error] [pid 2661205:tid 2661205] [client 217.64.126.24:61524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.215"] [uri "/.env"] [unique_id "anxE7iXLGHs8VFdwiRfL2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 09:40:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 217.64.126.24 (unassigned): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 217.64.126.24 (unassigned): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 05:40:50.595154 2026] [security2:error] [pid 697002:tid 697002] [client 217.64.126.24:64628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.5"] [uri "/.env"] [unique_id "anw_okkVzWbYQQVVv24VuAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LSPCCU
2026-08-12 09:34:15
(1 month ago)
TSEC Honeypot Network report. Threat score: 81/100. Categories: Port Scan, Hacking, Brute-Force, Web ...
show more
TSEC Honeypot Network report. Threat score: 81/100. Categories: Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: cowrie, ssh-telnet. Context: 217.64.126.24 classified as automated brute-force attacker targeting SSH/Telnet credentials (high confidence).
show less
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
๐ซ๐ท
Eldeberen
2026-08-12 08:59:41
(1 month ago)
Vulnerability scan attempt through HTTP protocol
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 08:47:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 217.64.126.24 (unassigned): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 217.64.126.24 (unassigned): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 04:47:34.168423 2026] [security2:error] [pid 298731:tid 298731] [client 217.64.126.24:60497] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.184"] [uri "/.env"] [unique_id "anwzJhNzVorOS-peR1fD4AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
FreeMyIP
2026-08-12 08:12:11
(1 month ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack