π¨π³
SA19999
2026-08-13 22:02:02
(1 week ago)
Auto-report: brute_force | sources=["peer-sync"] | Fox honeypot cluster
Web App Attack
π¦πΊ
dyln
2026-08-11 20:45:08
(1 week ago)
Dyls honeypot brute-force: RDP (2 total hits)
Brute-Force
Anonymous
2026-08-07 17:34:09
(2 weeks ago)
Portscan: TCP/2222 (5x), TCP/22 (5x)
Port Scan
πΊπΈ
LSPCCU
2026-08-07 16:54:05
(2 weeks ago)
TSEC Honeypot Network report. Threat score: 94/100. Categories: Port Scan, Hacking, Brute-Force, Web ...
show more
TSEC Honeypot Network report. Threat score: 94/100. Categories: Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: cowrie, ssh-telnet. Context: Attacker IP from Hangzhou, China (AS37963, Hangzhou Alibaba Advertising Co.
show less
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
πΊπΈ
TPI-Abuse
2026-08-07 00:52:01
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 20:51:54.945581 2026] [security2:error] [pid 6330:tid 6330] [client 47.96.143.58:49720] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||sjjcox.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sjjcox.com"] [uri "/"] [unique_id "anUsKkevB1t7HBIu_iL2igAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
alferez
2026-08-06 22:49:24
(2 weeks ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-06 22:47:24
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 18:47:16.191121 2026] [security2:error] [pid 1323263:tid 1323263] [client 47.96.143.58:57218] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||sharawi-gum.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sharawi-gum.com"] [uri "/"] [unique_id "anUO9Ie6XEnrNS9ErrHQMAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
anycast_ac
2026-08-06 22:32:27
(2 weeks ago)
[WebProtection] L4/L7 attack source Β· PROTO-443-SILENT-DROP Β· 5 hits/window
Port Scan
πΊπΈ
TPI-Abuse
2026-08-06 21:59:30
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 17:59:24.130611 2026] [security2:error] [pid 3654142:tid 3654142] [client 47.96.143.58:54542] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||sublimetiles.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sublimetiles.com"] [uri "/"] [unique_id "anUDvB8KsXvvfcE9Zz20wAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-06 21:50:49
(2 weeks ago)
Multiple WAF Violations
Web App Attack
π«π·
masterguru
2026-08-06 20:56:37
(2 weeks ago)
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(? ...
show more
Multiple/Conflicting Connection Header Data Found. Pattern match "\\\\b(?:keep-alive|close),\\\\s?(?:keep-alive|close)\\\\b" at REQUEST_HEADERS:Connection. (920210-195)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-06 20:26:08
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 16:26:01.911868 2026] [security2:error] [pid 3290598:tid 3290598] [client 47.96.143.58:45284] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||handcraftedparquet.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "handcraftedparquet.com"] [uri "/"] [unique_id "anTt2fUvmQUG1sTZqP-RjgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-06 18:45:01
(2 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-06 18:15:00
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.96.143.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 14:14:52.950754 2026] [security2:error] [pid 3205416:tid 3205416] [client 47.96.143.58:56304] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jffinnovations.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jffinnovations.com"] [uri "/"] [unique_id "anTPHO6wSqb6dYTAFVyR2wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-06 18:05:29
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking