🇫🇷
SpaceHost-Server
2026-09-09 22:19:33
(1 hour ago)
Brute-Force
Web App Attack
🇫🇷
agroman93
2026-09-09 21:49:19
(2 hours ago)
SSH honeypot: automated brute-force login attempts against a decoy server. Source seen attacking a p ...
show more
SSH honeypot: automated brute-force login attempts against a decoy server. Source seen attacking a public sensor.
show less
Brute-Force
SSH
Anonymous
2026-09-09 07:52:42
(16 hours ago)
Fail2Ban triggered
Web App Attack
🇩🇪
nidaren
2026-09-09 07:42:56
(16 hours ago)
34.156.178.35 - - [09/Sep/2026:09:42:52 +0200] "\x16\x03\x00\x00i\x01\x00\x00e\x03\x03U\x1C\xA7\xE4r ...
show more
34.156.178.35 - - [09/Sep/2026:09:42:52 +0200] "\x16\x03\x00\x00i\x01\x00\x00e\x03\x03U\x1C\xA7\xE4random1random2random3random4\x00\x00\x0C\x00/\x00" 400 150 "-" "-"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
dinginess6354
2026-09-09 07:29:35
(16 hours ago)
Unauthorized Access Attempt
Port Scan
Hacking
Web App Attack
🇬🇧
Interceptor_HQ
2026-09-09 07:16:32
(16 hours ago)
request_uri: / -- automatic report --
Brute-Force
Hacking
🇸🇬
WMK965
2026-09-09 07:00:14
(16 hours ago)
34.156.178.35 - - [09/Sep/2026:15:00:08 +0800] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x035\x1B\x9 ...
show more
34.156.178.35 - - [09/Sep/2026:15:00:08 +0800] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x035\x1B\x98\xDB\x1A@q\xED\x8CIW\xD7\xDBe\xDBv\xDFx\x9F~b#r\xE0q\xC8\xE5\x01 .:Q ,{\xFA'\x9F\x87\xAE\xAB\xC0_\x97\x05\xB3\x85\x97F\xEB}?L\xAB\xD9\xC5\xC9H\x05C\xFB\x14v\xE4\xB2\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 154 "-" "-" "-"
34.156.178.35 - - [09/Sep/2026:15:00:13 +0800] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 154 "-" "-" "-"
34.156.178.35 - - [09/Sep/2026:15:00:14 +0800] "\xC0\x83w\x86\x8DhBi]\xA4\xCC)\xF2d\xE3\x95\x12\xEA\xC7:F\x17AH\x1C\xBF[8\x0C\x9C P\xC7\x8F s\xB1(\xC3>\xEF\xF8\xBAMH\x1F\xF8\xCF]\x90a\x86z+\xF7;\xDA\x0E\xD8\xDA\x95\x80L\x83" 400 154 "-" "-" "-"
show less
Port Scan
Web App Attack
🇹🇷
pashait
2026-09-09 06:59:52
(16 hours ago)
Auto-blocked by Seczar SecureOps — IPS Web Attack Signature (1 events in 5min) at 2026-09-09 06:59
Web App Attack
Bad Web Bot
🇩🇪
MaxMeier
2026-09-09 06:52:00
(17 hours ago)
34.156.178.35 - - [09/Sep/2026:08:49:39 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
34.156.178.35 - - [09/Sep/2026:08:49:39 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.156.178.35 - - [09/Sep/2026:08:49:40 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03'b\xB3\xBF\x9EVP\xA5E\xDB\x10s\x8D\xB6\x11\x14\xC5\x01\xAE\xB7o\x9BL\xF3\xE3~\x07\xC6\x88\x97\xABy \xF8w\x0E^T\xE8`\xCB\xB3\xF7\x0C\xAA\xF9\xF4\xDA\x90R\x89Q\x14\x01\x1F\xFC\xEE\x1F\xFE6)\x16\x91\x12\xA3\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
34.156.178.35 - - [09/Sep/2026:08:49:41 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.156.178.35 - - [09/Sep/2026:08:49:45 +0200] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-"
...
show less
Bad Web Bot
Web App Attack
🇵🇱
ToJa
2026-09-09 06:47:33
(17 hours ago)
Web App Port Scaning, Access Not Existent Virtual Server. (honeypot)::
34.156.178.35 - - [09/Sep/202 ...
show more
Web App Port Scaning, Access Not Existent Virtual Server. (honeypot)::
34.156.178.35 - - [09/Sep/2026:08:47:32 +0200] "GET / HTTP/1.1" 200 35 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
show less
Web App Attack
🇬🇧
essinghigh
2026-09-09 06:46:17
(17 hours ago)
IPS Detection: 34.156.178.35 -> DPT: 80
Port Scan
🇩🇪
0x44
2026-09-09 06:23:51
(17 hours ago)
Abusive host detected - Web probing for vulnerabilities
Web App Attack
Hacking
🇺🇸
HamSammich
2026-09-09 05:59:12
(17 hours ago)
Automated sensor: 1 HTTP connection/probe attempts over the last 24h (latest 2026-09-09T05:59Z).
Brute-Force
Web App Attack
🇳🇴
jad-abuse
2026-09-09 05:48:08
(18 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: tls_scann ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: tls_scanner. Observed by 1 sensor(s); 5 hits.
show less
Port Scan
Bad Web Bot
🇺🇸
cwytech
2026-09-09 05:36:23
(18 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/tactical-rmm-lockdown-high.
Hacking