|
๐บ๐ธ
gu-alvareza
|
|
Java.Debug.Wire.Protocol.Insecure.Configuration
|
Hacking
|
|
|
๐ฒ๐ฝ
impra
|
|
Detected 71 connection attempts across 9 ports.
|
Port Scan
Hacking
Web App Attack
|
|
|
Anonymous
|
|
Fuzzing/Looking for credentials files.
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
[09/Jun/2026:05:20:53 +1000] "\x16\x03" 400 266
|
Hacking
Web App Attack
|
|
|
๐ฉ๐ช
Serpentex
|
|
34.78.179.125 - - [08/Jun/2026:20:40:44 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03UR\xA40\ ...
show more
34.78.179.125 - - [08/Jun/2026:20:40:44 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03UR\xA40\xFD\xC7\xFA\x9Dzh\xA2\xB5\xCB:s\xE6\xD8\xC5\x99\x02\x8B\x17\xE1\xB4P\xEF\xAF\x83\x92\x5CS\xCA _\x00\xD6@\x10\x80\xE66!\xBC9\x88\x03\xF1Q\xEA\xF2Pt'Z\xB9\x09{v+\xB3\xF5\xFD\xA8\xAD\xCB\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-"
34.78.179.125 - - [08/Jun/2026:20:40:48 +0200] "\xCD!\x1B\xCE\xDC\x81\x04\xC2\xBA~\xC4\xCDU\xD6{\xEC\xC1\xFC_8\xC8\x94R$\x05\xFA\x09D\xC2\xA2\x14o\x83\xD9:&^s\xE1r\xCD\xDE]\xC5\xAE\xC44K\xA3\xF0~\x9E\xD3\xB8!\xC3\xF0;\xA7Bx\x1C\x1Fr" 400 150 "-" "-"
34.78.179.125 - - [08/Jun/2026:20:40:49 +0200] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-"
...
show less
|
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
[Mon Jun 08 20:35:26.847627 2026] [authz_core:error] [pid 111097:tid 111122] [client 34.78.179.125:5 ...
show more
[Mon Jun 08 20:35:26.847627 2026] [authz_core:error] [pid 111097:tid 111122] [client 34.78.179.125:5986] AH01630: client denied by server configuration: /var/www/html/
[Mon Jun 08 20:35:27.007246 2026] [authz_core:error] [pid 111097:tid 111105] [client 34.78.179.125:23678] AH01630: client denied by server configuration: /var/www/html/
[Mon Jun 08 20:35:27.159696 2026] [authz_core:error] [pid 118553:tid 118562] [client 34.78.179.125:23680] AH01630: client denied by server configuration: /var/www/html/
[Mon Jun 08 20:35:27.311503 2026] [authz_core:error] [pid 118553:tid 118576] [client 34.78.179.125:23706] AH01630: client denied by server configuration: /var/www/html/
[Mon Jun 08 20:35:27.519584 2026] [authz_core:error] [pid 111097:tid 111101] [client 34.78.179.125:23718] AH01630: client denied by server configuration: /var/www/html/
...
show less
|
Web App Attack
|
|
|
๐ฆ๐บ
dyln
|
|
Dyls honeypot brute-force: proto8 (1 total hits)
|
Brute-Force
|
|
|
Anonymous
|
|
34.78.179.125 - - [08/Jun/2026:17:26:08 +0000] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x8E\xAD ...
show more
34.78.179.125 - - [08/Jun/2026:17:26:08 +0000] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x8E\xAD\xB1\xF7\xB7\x87\xE8NU\x18?\xA7Et\x102\xC6\xC1\xC9\xE2\xC5\xF2\x8E\xFF!\x01\x1F\xE3\xB4i~\x91 I\x9F\xDF~T\xB5\x18\xAD\xC3\xBB\xF1W\xBC\xD6\x96\xBD\x91o\x07\x85:\xF9\x13\xCA\x11\x0E\x91-\xC0Q!\x9E\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-" "-"
34.78.179.125 - - [08/Jun/2026:17:26:15 +0000] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-" "-"
...
show less
|
Port Scan
Brute-Force
|
|
|
๐บ๐ธ
Starburst SysOp Team
|
|
Host header is a numeric IP address. Pattern match "(?:^( (920350-stl2-14)
|
Hacking
Bad Web Bot
|
|
|
๐บ๐ธ
antlac1
|
|
crowdsecurity/http-probing
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
raspi4
|
|
Fail2Ban Ban Triggered
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
Roper123
|
|
Web exploits
|
Web App Attack
|
|
|
๐ต๐น
nuno
|
|
34.78.179.125 - - [08/Jun/2026:16:19:34 +0100] host:80 "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Wind ...
show more
34.78.179.125 - - [08/Jun/2026:16:19:34 +0100] host:80 "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.000 -
34.78.179.125 - - [08/Jun/2026:16:19:35 +0100] host:80 "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.000 -
...
show less
|
Web App Attack
|
|
|
๐บ๐ธ
nyt
|
|
Empty UA + error
|
Web App Attack
|
|
|
๐ธ๐ช
Esko
|
|
34.78.179.125 - - [08/Jun/2026:14:30:12 +0000] "\x16\x03\x00\x00i\x01\x00\x00e\x03\x03U\x1C\xA7\xE4r ...
show more
34.78.179.125 - - [08/Jun/2026:14:30:12 +0000] "\x16\x03\x00\x00i\x01\x00\x00e\x03\x03U\x1C\xA7\xE4random1random2random3random4\x00\x00\x0C\x00/\x00" 400 150 "-" "-"
show less
|
Web App Attack
|
|