π©πͺ
HoneyPot-FrPri
2026-02-03 21:46:20
(6 months ago)
2026-02-03T22:46:19.093977+01:00 [redacted] sshd[1344766]: Connection closed by 2a06:4882:5000::4b p ...
show more
2026-02-03T22:46:19.093977+01:00 [redacted] sshd[1344766]: Connection closed by 2a06:4882:5000::4b port 56339
2026-02-03T22:46:19.183630+01:00 [redacted] sshd[1344767]: Connection closed by 2a06:4882:5000::
...
show less
Brute-Force
SSH
πΊπΈ
chronos
2026-02-02 06:33:59
(6 months ago)
[AUTORAVALT][[02/02/2026 - 03:33:58 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Ph ...
show more
[AUTORAVALT][[02/02/2026 - 03:33:58 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Phishing -> Phishing websites and/or email.
Email Spam -> Spam email content, infected attachments, and phishing emails.
Hacking... Unauthorized attempts to access the server.
Spoofing -> Email sender spoofing.
Brute-Force -> Credential brute-force attacks on webpa]
...
show less
Phishing
Email Spam
Hacking
Spoofing
Brute-Force
πΊπΈ
chronos
2026-02-02 02:14:53
(6 months ago)
[AUTORAVALT][[01/02/2026 - 23:14:53 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Ph ...
show more
[AUTORAVALT][[01/02/2026 - 23:14:53 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Phishing -> Phishing websites and/or email.
Email Spam -> Spam email content, infected attachments, and phishing emails.
Hacking... Unauthorized attempts to access the server.
Spoofing -> Email sender spoofing.
Brute-Force -> Credential brute-force attacks on webpa]
...
show less
Phishing
Email Spam
Hacking
Spoofing
Brute-Force
Anonymous
2026-01-29 19:52:12
(6 months ago)
2026-01-29T20:52:03.477316+01:00 vmi-radio sshd-session[877029]: refused connect from 2a06:4882:5000 ...
show more
2026-01-29T20:52:03.477316+01:00 vmi-radio sshd-session[877029]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4b)
2026-01-29T20:52:08.547864+01:00 vmi-radio sshd-session[877048]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4b)
2026-01-29T20:52:11.569132+01:00 vmi-radio sshd-session[877063]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4b)
...
show less
Brute-Force
SSH
π«π·
bgg
2026-01-25 10:20:38
(7 months ago)
Jan 25 11:20:37 nanopirate sshd[11729]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4b) ...
show more
Jan 25 11:20:37 nanopirate sshd[11729]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4b)
...
show less
Brute-Force
SSH
π«π·
bgg
2026-01-13 08:55:34
(7 months ago)
Jan 13 09:55:34 nanopirate sshd[1256669]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4 ...
show more
Jan 13 09:55:34 nanopirate sshd[1256669]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4b)
...
show less
Brute-Force
SSH
π¨π
SOC [GOLINE SA]
2026-01-12 21:53:26
(7 months ago)
Suricata IDS Detection: πΎ - π¨ Suspicious π HTTP trafic on unusual HTTP port
=== ATTACK DETAILS ===
...
show more
Suricata IDS Detection: πΎ - π¨ Suspicious π HTTP trafic on unusual HTTP port
=== ATTACK DETAILS ===
Signature: πΎ - π¨ Suspicious π HTTP trafic on unusual HTTP port
Signature ID: 3300303
Severity: 1
Category: Potential Corporate Privacy Violation
=== NETWORK INFO ===
Source IP: 2a06:4882:5000::4b (IPv6)
Source Port: 33411
Target: passbolt.goline.ch (2a02:4460:0001:0001:0000:0000:0000:0033)
Target Port: 10000
Protocol: TCP
App Protocol: http
=== DETECTION ===
System: Suricata IDS
Time: 2026-01-12 22:53:25
Status: Banned by Fail2Ban
show less
Port Scan
Hacking
Bad Web Bot
π¨π
SOC [GOLINE SA]
2026-01-12 08:12:32
(7 months ago)
Suricata IDS Detection: πΎ - π¨ Suspicious π HTTP trafic on unusual HTTP port
=== ATTACK DETAILS ===
...
show more
Suricata IDS Detection: πΎ - π¨ Suspicious π HTTP trafic on unusual HTTP port
=== ATTACK DETAILS ===
Signature: πΎ - π¨ Suspicious π HTTP trafic on unusual HTTP port
Signature ID: 3300303
Severity: 1
Category: Potential Corporate Privacy Violation
=== NETWORK INFO ===
Source IP: 2a06:4882:5000::4b (IPv6)
Source Port: 33411
Target: passbolt.goline.ch (2a02:4460:0001:0001:0000:0000:0000:0033)
Target Port: 10000
Protocol: TCP
App Protocol: http
=== DETECTION ===
System: Suricata IDS
Time: 2026-01-12 09:12:30
Status: Banned by Fail2Ban
show less
Port Scan
Hacking
Bad Web Bot
πΊπΈ
chronos
2026-01-12 06:41:37
(7 months ago)
[AUTORAVALT][[12/01/2026 - 03:41:36 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Ph ...
show more
[AUTORAVALT][[12/01/2026 - 03:41:36 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Phishing -> Phishing websites and/or email.
Email Spam -> Spam email content, infected attachments, and phishing emails.
Hacking... Unauthorized attempts to access the server.
Spoofing -> Email sender spoofing.
Brute-Force -> Credential brute-force attacks on webpa]
...
show less
Phishing
Email Spam
Hacking
Spoofing
Brute-Force
π©πͺ
Viveronese
2026-01-08 17:48:33
(7 months ago)
SASL LOGIN authentication failed
Brute-Force
πΊπΈ
chronos
2026-01-05 06:38:53
(7 months ago)
[AUTORAVALT][[05/01/2026 - 03:38:53 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Ph ...
show more
[AUTORAVALT][[05/01/2026 - 03:38:53 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Phishing -> Phishing websites and/or email.
Email Spam -> Spam email content, infected attachments, and phishing emails.
Hacking... Unauthorized attempts to access the server.
Spoofing -> Email sender spoofing.
Brute-Force -> Credential brute-force attacks on webpa]
...
show less
Phishing
Email Spam
Hacking
Spoofing
Brute-Force
πΊπΈ
chronos
2025-12-29 20:47:05
(7 months ago)
[AUTORAVALT][[29/12/2025 - 17:47:05 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Ph ...
show more
[AUTORAVALT][[29/12/2025 - 17:47:05 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Phishing -> Phishing websites and/or email.
Email Spam -> Spam email content, infected attachments, and phishing emails.
Hacking... Unauthorized attempts to access the server.
Spoofing -> Email sender spoofing.
Brute-Force -> Credential brute-force attacks on webpa]
...
show less
Phishing
Email Spam
Hacking
Spoofing
Brute-Force
πΊπΈ
chronos
2025-12-29 06:34:49
(7 months ago)
[AUTORAVALT][[29/12/2025 - 03:34:48 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Ph ...
show more
[AUTORAVALT][[29/12/2025 - 03:34:48 -03:00 UTC]
Attack from [2a06:4882:5000::4b] Action: BLocKed
Phishing -> Phishing websites and/or email.
Email Spam -> Spam email content, infected attachments, and phishing emails.
Hacking... Unauthorized attempts to access the server.
Spoofing -> Email sender spoofing.
Brute-Force -> Credential brute-force attacks on webpa]
...
show less
Phishing
Email Spam
Hacking
Spoofing
Brute-Force
π«π·
bgg
2025-12-28 21:31:01
(7 months ago)
Dec 28 22:31:01 nanopirate sshd[1688655]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4 ...
show more
Dec 28 22:31:01 nanopirate sshd[1688655]: refused connect from 2a06:4882:5000::4b (2a06:4882:5000::4b)
...
show less
Brute-Force
SSH
π¬π§
Birdo
2025-12-28 17:47:00
(7 months ago)
[Birdo SSH Honeypot] SSH login attempt
Port Scan
Hacking
Brute-Force
Exploited Host
SSH