๐ฆ๐น
urnilxfgbez
2026-06-03 22:45:00
(2 weeks ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
๐ฌ๐ง
PeravixGroup
2026-06-02 21:59:45
(2 weeks ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8443. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8443. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
๐บ๐ธ
pixiekat
2026-06-02 21:13:21
(2 weeks ago)
[Tue Jun 02 21:13:14.012969 2026] [authz_core:error] [pid 72868:tid 72871] [client 52.179.88.121:524 ...
show more
[Tue Jun 02 21:13:14.012969 2026] [authz_core:error] [pid 72868:tid 72871] [client 52.179.88.121:52483] AH01630: client denied by server configuration: /var/www/html/.env.local
[Tue Jun 02 21:13:15.576154 2026] [authz_core:error] [pid 72868:tid 72888] [client 52.179.88.121:52509] AH01630: client denied by server configuration: /var/www/html/.env.production
[Tue Jun 02 21:13:17.842191 2026] [authz_core:error] [pid 72868:tid 72872] [client 52.179.88.121:52516] AH01630: client denied by server configuration: /var/www/html/.env.backup
[Tue Jun 02 21:13:20.112435 2026] [authz_core:error] [pid 72868:tid 72881] [client 52.179.88.121:52482] AH01630: client denied by server configuration: /var/www/html/.env.save
[Tue Jun 02 21:13:21.047177 2026] [authz_core:error] [pid 72868:tid 72893] [client 52.179.88.121:52493] AH01630: client denied by server configuration: /var/www/html/wp-config.php
...
show less
Brute-Force
๐ฎ๐ช
AutosOnShow
2026-06-02 20:40:07
(2 weeks ago)
blocked for webapp attack | path requested: /.env | seen at 2026-06-02 20:39:28.944 |
Web App Attack
๐ณ๐ฑ
soverin
2026-06-02 19:38:55
(2 weeks ago)
Network scan on port 80
Email Spam
Anonymous
2026-06-02 19:25:02
(2 weeks ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-02 19:09:02
(2 weeks ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-iad5-2)
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-02 19:06:38
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 52.179.88.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 52.179.88.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 15:06:32.072489 2026] [security2:error] [pid 15658:tid 15679] [client 52.179.88.121:52480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.79"] [uri "/.git/HEAD"] [unique_id "ah8puMSVoBJPYWbjfrArmQAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-06-02 18:57:36
(2 weeks ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
๐บ๐ธ
RAP
2026-06-02 18:05:47
(2 weeks ago)
2026-06-02 18:05:47 UTC Unauthorized activity to TCP port 8443. Web App
Port Scan
Web App Attack
๐ซ๐ท
dynamix
2026-06-02 17:36:49
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:23:38
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 52.179.88.121 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 52.179.88.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:23:30.521935 2026] [security2:error] [pid 10646:tid 10646] [client 52.179.88.121:52941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.150"] [uri "/.git/config"] [unique_id "ah8Rkms3PAMHHjyezGXunAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 16:59:23
(2 weeks ago)
Jun 2 12:59:23 localhost kernel: [108764879.702101] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
Jun 2 12:59:23 localhost kernel: [108764879.702101] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=52.179.88.121 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=40 ID=22494 DF PROTO=TCP SPT=53192 DPT=2082 WINDOW=64240 RES=0x00 SYN URGP=0
Jun 2 12:59:23 localhost kernel: [108764879.702110] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=52.179.88.121 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=40 ID=22494 DF PROTO=TCP SPT=53192 DPT=2082 SEQ=4229654593 ACK=0 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405A00402080A5F4D2224000000000103030A)
Jun 2 12:59:23 localhost kernel: [108764879.833458] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=52.179.88.121 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=45 ID=13457 DF PROTO=TCP SPT=53213 DPT=8443 WINDOW=64240 RES=0x00 SYN URGP=0
Jun 2 12:59:23 localhost kernel: [108764879.833466] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0
show less
Port Scan
Anonymous
2026-06-02 16:57:13
(2 weeks ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
kosada.com
2026-06-02 16:31:07
(2 weeks ago)
Web vulnerability probing: /phpinfo.php (bogus vhost/SNI)
Web App Attack