Anonymous
2026-06-12 08:33:46
(2 days ago)
Probing for known exploit paths (.env, .git, wp-admin, shell files, etc.). Single-strike ban policy ...
show more
Probing for known exploit paths (.env, .git, wp-admin, shell files, etc.). Single-strike ban policy โ zero tolerance for exploit scanning. Banned Jun 12, 08:33 UTC. Origin: Belgium, Brussels.
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-06-12 08:12:37
(2 days ago)
This IP was detected by CrowdSec triggering custom/ip-honeypot
Web App Attack
Bad Web Bot
๐ง๐ท
mubusys.com
2026-06-12 07:43:08
(2 days ago)
35.205.42.214 - - [12/Jun/2026:04:42:57 -0300] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03&1%\xD5J ...
show more
35.205.42.214 - - [12/Jun/2026:04:42:57 -0300] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03&1%\xD5J\xCE}\xF6\xEA\x03\xC7\x93q\xC8\x8Ag\x85\xAF\xB6T:\xB2\xCE\xF8.\xA2^\x1F\x0B\x82,\xB9 \x5CU\x80\xCF\x900\x956\xB9\xAECVWr7-\x00\xC9ic\xC7L\x1D\xFF\xB5\xE5\x80\xB4\x8E\x86,\xBE\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 157 "-" "-" "-"
35.205.42.214 - - [12/Jun/2026:04:43:02 -0300] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 157 "-" "-" "-"
show less
Hacking
Brute-Force
๐ณ๐ฑ
knock
2026-06-12 07:28:36
(2 days ago)
Knock-Knock honeypot brute-force: proto8 (1 total hits)
Brute-Force
๐บ๐ธ
gu-alvareza
2026-06-12 07:05:27
(2 days ago)
Java.Debug.Wire.Protocol.Insecure.Configuration
Hacking
๐จ๐ณ
WMK965
2026-06-12 07:04:48
(2 days ago)
35.205.42.214 - - [12/Jun/2026:15:04:40 +0800] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03n@jn*\xF ...
show more
35.205.42.214 - - [12/Jun/2026:15:04:40 +0800] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03n@jn*\xF0I:\x1Ei\x17\xB2\x1E}\x07\xFF\xBE\x018\xEB\xA5\x1Bh\xEC`\xA4\xDCNQz\xE0\xE0 \xB5\x17D\xF1\x1B\xDD\xF1\xB9\xDEekP\x1E[N@E\x0E\xDDc\x90I\xAF}Q\xAE\x1F\xA9>kZm\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 154 "-" "-" "-"
35.205.42.214 - - [12/Jun/2026:15:04:46 +0800] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 154 "-" "-" "-"
35.205.42.214 - - [12/Jun/2026:15:04:47 +0800] "\xCA-\x94\xCA\x16f\xF4\xDE\x8F\xF8\xEE#kE\xEA\xE3nN\x98\xD9\xC7\x86\x80)\xC3\xF9z\x80\x98\x09\xBC_R\xF7g\xF1q\xEA\xCE\xA8B\x8Cl\xCB\xFD\xC5\xA5\xD48\x1Br\x82\x91f" 400 154 "-" "-" "-"
show less
Port Scan
Web App Attack
๐ฉ๐ช
Ano_Nym
2026-06-12 06:55:52
(2 days ago)
CrowdSec IDS alert on VPS 85.215.198.123 (DE). Scenario: crowdsecurity/http-probing
Web App Attack
๐ต๐ฑ
mkey
2026-06-12 06:41:45
(2 days ago)
[First: 2026-06-12 04:07:10/single] HITS=1 Repeated suspicious IDS-detected activity; sample=WEB-ATA ...
show more
[First: 2026-06-12 04:07:10/single] HITS=1 Repeated suspicious IDS-detected activity; sample=WEB-ATACK: Invalid destination host in header
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
xxkodedxx
2026-06-12 06:24:26
(2 days ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 2ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 2ร edge-block in 10m window.
Origin: BE / AS396982 Google LLC
Active: 06:24:00โ06:24:06 UTC
Volume: 2 HTTP req
Probed: /
Status mix: 444ร2
Vhost fishing: 67.217.240.72
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-06-12 06:22:34
(2 days ago)
Empty UA + error
Web App Attack
๐ฌ๐ง
Interceptor_HQ
2026-06-12 06:10:59
(2 days ago)
request_uri: / -- automatic report --
Brute-Force
Hacking
๐บ๐ธ
bulkvm.com
2026-06-12 06:10:49
(2 days ago)
[bulkvm.com/honeypot] Generic HTTP. Port: 32018, request: GET / HTTP/1.1
, user-agent: Mozilla/5.0 ( ...
show more
[bulkvm.com/honeypot] Generic HTTP. Port: 32018, request: GET / HTTP/1.1
, user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64, Time: 2026-06-12 06:10:39 UTC
show less
Hacking
๐ซ๐ท
pm33
2026-06-12 06:01:21
(2 days ago)
Unsolicited connection attempts or aggressive port scan.
Port Scan
๐ซ๐ท
pm33
2026-06-12 04:49:44
(2 days ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐ต๐น
nuno
2026-06-12 03:10:35
(2 days ago)
35.205.42.214 - - [12/Jun/2026:04:10:33 +0100] host:80 "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Wind ...
show more
35.205.42.214 - - [12/Jun/2026:04:10:33 +0100] host:80 "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.000 -
35.205.42.214 - - [12/Jun/2026:04:10:34 +0100] host:80 "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.000 -
...
show less
Web App Attack