π«π·
Bensay
2026-10-08 19:59:12
(2 days ago)
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show more
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=unknown
show less
Port Scan
π³π΄
noteng.no
2026-10-03 11:08:58
(1 week ago)
34.140.129.234 - - [03/Oct/2026:13:08:53 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xA0\xC ...
show more
34.140.129.234 - - [03/Oct/2026:13:08:53 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xA0\xCCj\xF6s\xCD\x8A\xA0\x85\xF5y\xD2\x13\xA5\xD5\x94Xy\xC9\xCD\xC9\x1AS1\xE3\xB2\xBDjP\xA9\x17\xD6 Z\x16\xEC2\xBB\x1DyU\xD5;\xDE\xB8a\x94k\xD5\xD4\xAB\xBF\xA2y\x0B\x14\x06H>.\xD3\xD9\xA9\xE2\x13\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
34.140.129.234 - - [03/Oct/2026:13:08:58 +0200] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-"
34.140.129.234 - - [03/Oct/2026:13:08:58 +0200] "\x84\x80\xF5\xB5\x05\xA7\xCE\xA7l1\x1C\x12\xD3@\xBFK\x5Ck\x1D5H\x11U\xF2\xFC\xAF\x81\xB6eg\x86!M(\x22\x04E\xCD.\x0F\x97C,\xEC4y\x8F\xED=\xF0~O\x91\x1A\xC6\x11.+^z\xE5\xCBj " 400 150 "-" "-"
...
show less
Hacking
Web App Attack
π³π±
knock
2026-10-03 07:39:29
(1 week ago)
Knock-Knock honeypot brute-force: HTTP (1 total hits)
Web App Attack
π§π·
somosbr
2026-10-03 07:10:33
(1 week ago)
[2026-10-03T07:10:33Z] Unsolicited scan from 34.140.129.234 to port 80/tcp
Port Scan
π³π±
donarev419
2026-10-03 06:40:46
(1 week ago)
Connection to port 80 with data transfer.
Data preview: GET / HTTP/1.1
Host: 87.229.95.155:80
User ...
show more
Connection to port 80 with data transfer.
Data preview: GET / HTTP/1.1
Host: 87.229.95.155:80
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleW
show less
Port Scan
Hacking
π«π·
masterguru
2026-10-03 05:41:32
(1 week ago)
Host header is a numeric IP address. Pattern match "^ (920350-131)
Hacking
Bad Web Bot
π¨π¦
lakered
2026-10-03 05:40:16
(1 week ago)
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol ...
show more
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evidence: High-Criminality-Signature (p0f:*:64:0:*:mss*30,7:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.98), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:7978m)
show less
Port Scan
Exploited Host
πΊπΈ
legionMCCXV
2026-10-03 05:12:43
(1 week ago)
Non-HTTP protocol data (e.g. MQTT/TLS handshake bytes) sent to HTTP(S) port.
Port Scan
Hacking
πΊπΈ
NXTwoThou
2026-10-03 05:08:20
(1 week ago)
166.203
Web App Attack
πΊπΈ
gu-alvareza
2026-10-03 05:07:06
(1 week ago)
Java.Debug.Wire.Protocol.Insecure.Configuration
Hacking
πΊπΈ
aks4226
2026-10-03 05:01:38
(1 week ago)
Attacking common web applications. (n01)
Web App Attack
π§π·
mubusys.com
2026-10-03 04:39:29
(1 week ago)
34.140.129.234 - - [03/Oct/2026:01:39:23 -0300] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x06\xC ...
show more
34.140.129.234 - - [03/Oct/2026:01:39:23 -0300] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x06\xCB\x9E\xF8\x06+ \xF6\x9B\xD9" 400 157 "-" "-" "-"
34.140.129.234 - - [03/Oct/2026:01:39:29 -0300] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 157 "-" "-" "-"
show less
Hacking
Brute-Force
π¨π¦
smithoo4
2026-10-03 04:38:50
(1 week ago)
34.140.129.234 - - [03/Oct/2026:00:38:48 -0400] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT ...
show more
34.140.129.234 - - [03/Oct/2026:00:38:48 -0400] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.140.129.234 - - [03/Oct/2026:00:38:49 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xB1z\x8A\xD5$]=\xBC\xFB\xBF/r\xE8\x89\x1F\xDE\x9D\x9F\xFAq?\xC0\x96\xBC\xE2\x19\x84\xC3\x93(P\xDF \xF8\xED\xD6\x06\xBE\x04A.\x88G\x09\xFD\x12\x89ZB\xEC\xE2i\xFA\xB0\xB3\xF1\xEA\xB9\x8A\xCA\x90\xB5D\x88\x00\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
...
show less
Port Scan
Bad Web Bot
π¬π§
cybersteve99
2026-10-03 04:37:17
(1 week ago)
Too many 4xx Requests -
Brute-Force
Web App Attack
π³π΄
jad-abuse
2026-10-03 04:17:42
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: tls_scann ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: tls_scanner. Observed by 1 sensor(s); 5 hits.
show less
Port Scan
Bad Web Bot