πΊπΈ
LSPCCU
2026-09-11 09:16:57
(1 week ago)
TSEC Honeypot Network report. Threat score: 73/100. Categories: DDoS Attack, Port Scan, Hacking, Bru ...
show more
TSEC Honeypot Network report. Threat score: 73/100. Categories: DDoS Attack, Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: tanner. Context: 34.62.112.164 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
DDoS Attack
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
πΊπΈ
donarev419
2026-09-11 07:29:36
(1 week ago)
Connection to port 80 with data transfer.
Data preview: GET / HTTP/1.1
Host: 167.253.66.144:80
Use ...
show more
Connection to port 80 with data transfer.
Data preview: GET / HTTP/1.1
Host: 167.253.66.144:80
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Apple
show less
Port Scan
Hacking
π§π·
SOC Blue Team
2026-09-11 07:26:01
(1 week ago)
IPs get by Hunting on SIEM
Phishing
Web Spam
Port Scan
Hacking
π©πͺ
sojan
2026-09-11 07:18:00
(1 week ago)
34.62.112.164 - - [11/Sep/2026:09:17:36 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03i\xB1>\x ...
show more
34.62.112.164 - - [11/Sep/2026:09:17:36 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03i\xB1>\xCA\x04N\x91\xAC " 400 157 "-" "-"
34.62.112.164 - - [11/Sep/2026:09:17:41 +0200] "\xE0\xA9\xB4s\x883$,\xC1\x16\xBDV\xFD\xBD.\x02G\x0BB\xE6\xAC+\xB8<Cj\xB3\xAE\xE6\x0C\x0B$\x97O\x1B\x15g\xA6\xE9\xE3\xAB\x0F\xC1\xEE\x922\xC0a\x7F\x03~\x8A\xC4!" 400 157 "-" "-"
34.62.112.164 - - [11/Sep/2026:09:17:59 +0200] "\x00\x1E\x06\x99\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x07version\x04bind\x00\x00\x10\x00\x03" 400 157 "-" "-"
...
show less
Bad Web Bot
π«π·
Faeeth
2026-09-11 07:14:43
(1 week ago)
Multiple hits on Honeypot UID:PTRW50NM46 Port:Http (80)
Brute-Force
π©πͺ
HoneyPotFRI
2026-09-11 06:39:10
(1 week ago)
34.62.112.164 - - [11/Sep/2026:08:39:09 +0200] "POST / HTTP/1.1" 405 157 "-" "Mozilla/5.0 (compatibl ...
show more
34.62.112.164 - - [11/Sep/2026:08:39:09 +0200] "POST / HTTP/1.1" 405 157 "-" "Mozilla/5.0 (compatible)"
34.62.112.164 [redacted] (396982-Google LLC Belgium Brussels) - - [11/Sep/2026:08:39:09 +0200]
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 06:23:31
(1 week ago)
crawler behavior: HTTP GET on a non-existent endpoint
Web App Attack
π¦πΉ
piqwjdas
2026-09-11 06:16:45
(1 week ago)
{"transaction":{"client_ip":"34.62.112.164","time_stamp":"Fri Sep 11 08:16:33 2026","server_id":"468 ...
show more
{"transaction":{"client_ip":"34.62.112.164","time_stamp":"Fri Sep 11 08:16:33 2026","server_id":"46824fc494f03034e6b98e26d7a2d7a06b25f0b7","client_port":2224,"host_ip":"212.186.116.154","host_port":80,"unique_id":"178910739387.409216","is_interrupted":false,"request":{"method":"GET","http_version":"1.1","hostname":"212.186.116.154","uri":"/","headers":{"Host":"212.186.116.154","User-Agent":"Mozilla/5.0 (compatible)","Connection":"close"}},"response":{"http_code":403,"headers":{"Server":"nginx\u0000","Date":"Fri, 11 Sep 2026 06:16:33 GMT","Content-Length":"146","Content-Type":"text/html","Connection":"close"}},"producer":{"modsecurity":"ModSecurity v3.0.16 (Linux)","connector":"ModSecurity-nginx v1.0.4","secrules_engine":"Enabled","components":["OWASP_CRS/4.30.0-dev\""]},"messages":[{"message":"Host header is a numeric IP address","details":{"match":"Matched \"Operator `Rx' with parameter `(?:^([\\d.]+|\\[[\\da-f:]+\\]|[\\da-f:]+)(:[\\d]+)?$)' against variable `REQUEST_HEADERS:Host' (Va
...
show less
Web App Attack
πΊπΈ
distorx
2026-09-11 06:14:48
(1 week ago)
[11/Sep/2026:06:14:47 +0000] 400 - - http localhost-nginx-proxy-manager "-" [Client 34.62.112.164] [ ...
show more
[11/Sep/2026:06:14:47 +0000] 400 - - http localhost-nginx-proxy-manager "-" [Client 34.62.112.164] [Length 154] [Gzip -] "-" "-"
...
show less
Port Scan
Bad Web Bot
πΊπΈ
IndigoRidge
2026-09-11 05:45:19
(1 week ago)
Knock-Knock HTTP honeypot activity; time=2026-09-11 05:40:29; http_method=GET; http_path=/; http_pur ...
show more
Knock-Knock HTTP honeypot activity; time=2026-09-11 05:40:29; http_method=GET; http_path=/; http_purpose=basic_probe; http_user_agent=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Sa
show less
Web App Attack
Anonymous
2026-09-11 05:42:22
(1 week ago)
34.62.112.164 - - [11/Sep/2026:07:42:21 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
34.62.112.164 - - [11/Sep/2026:07:42:21 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.62.112.164 - - [11/Sep/2026:07:42:21 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03-\xD8\x0B)\x96^\xCD\x82M\xE4~\xC0r}Gld\xC7X\x8FC\x86\xF2\xCB\x8D\x85\xBD\xFA\x89" 400 150 "-" "-"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
brantknudson.org
2026-09-11 05:39:03
(1 week ago)
Incorrect Host header
Web App Attack
Brute-Force
π©πͺ
AetherFox
2026-09-11 04:04:12
(1 week ago)
AetherFox VoidGuard detected: [Fri Sep 11 06:04:11.310691 2026] [authz_core:error] [pid 398572:tid 3 ...
show more
AetherFox VoidGuard detected: [Fri Sep 11 06:04:11.310691 2026] [authz_core:error] [pid 398572:tid 398578] [client 34.62.112.164:33888] AH01630: client denied by server configuration: /var/www/html/
[Fri Sep 11 06:04:11.310814 2026] [authz_core:error] [pid 398572:tid 398578] [client 34.62.112.164:33888] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Fri Sep 11 06:04:11.513370 2026] [authz_core:error] [pid 398573:tid 398620] [client 34.62.112.164:33894] AH01630: client denied by server configuration: /var/www/html/favicon.ico
[Fri Sep 11 06:04:11.513480 2026] [authz_core:error] [pid 398573:tid 398620] [client 34.62.112.164:33894] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Fri Sep 11 06:04:12.519070 2026] [authz_core:error] [pid 398573:tid 398614] [client 34.62.112.164:33910] AH01630: client denied by server configuration: /var/www/html/
...
show less
Bad Web Bot
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-09-11 04:03:01
(1 week ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [ice02]
Hacking
SQL Injection
Web App Attack
π©πͺ
Ilop
2026-09-11 04:00:03
(1 week ago)
[hp-100] 32 unsolicited packets to honeypot ports 80 (OCI DShield sensor)
Port Scan