๐ฉ๐ช
acadeova
2026-07-28 01:11:11
(10 hours ago)
๐จ Recon detected (nft drop)
SRC=52.238.24.38
Observed=TCP dpt=2087 in=enp0s6 ttl=41
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=52.238.24.38
Observed=TCP dpt=2087 in=enp0s6 ttl=41
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
KPS
2026-07-28 00:54:15
(11 hours ago)
PortscanN
Port Scan
๐ฉ๐ช
Holger
2026-07-28 00:21:32
(11 hours ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ท๐ธ
Scan
2026-07-27 23:59:55
(12 hours ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 23:30:37
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.238.24.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 52.238.24.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 19:30:30.216308 2026] [security2:error] [pid 304751:tid 304751] [client 52.238.24.38:58420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.181"] [uri "/.git/refs/heads/main"] [unique_id "amfqFpmwUiiMtypW_DRWegAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 23:12:23
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.238.24.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 52.238.24.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 19:12:19.064234 2026] [security2:error] [pid 826246:tid 826246] [client 52.238.24.38:58409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.209"] [uri "/.git/HEAD"] [unique_id "amfl02SkHPbo6m903k29UQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 21:38:59
(14 hours ago)
denied traffic to a honeypot network. destination port 80.
Port Scan
Hacking
๐ฉ๐ช
gadix
2026-07-27 21:36:49
(14 hours ago)
[27/Jul/2026:23:36:45.351980 +0200] amfPbRnE7_MTFOsmJZscpQAAAME 52.238.24.38 34920 127.0.0.1 7080
[2 ...
show more
[27/Jul/2026:23:36:45.351980 +0200] amfPbRnE7_MTFOsmJZscpQAAAME 52.238.24.38 34920 127.0.0.1 7080
[27/Jul/2026:23:36:46.082597 +0200] amfPbrb2mKB2azlKZhC2HwAAAIQ 52.238.24.38 34934 127.0.0.1 7080
[27/Jul/2026:23:36:47.249389 +0200] amfPbxnE7_MTFOsmJZscpgAAAMo 52.238.24.38 34940 127.0.0.1 7080
...
show less
Web App Attack
๐ง๐ท
Vieira Filho
2026-07-27 21:24:51
(14 hours ago)
52.238.24.38 - - [27/Jul/2026:18:24:51 -0300] [35.198.31.82] "35.198.31.82" "GET /.env.local HTTP/1 ...
show more
52.238.24.38 - - [27/Jul/2026:18:24:51 -0300] [35.198.31.82] "35.198.31.82" "GET /.env.local HTTP/1.1" 404 169 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0" 0.000
...
show less
Brute-Force
Web App Attack
Exploited Host
๐ซ๐ท
dynamix
2026-07-27 21:11:52
(14 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 20:55:51
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.238.24.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 52.238.24.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:55:47.715038 2026] [security2:error] [pid 754348:tid 754348] [client 52.238.24.38:58498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.148"] [uri "/.git/refs/heads/master"] [unique_id "amfF0zQK4OcF8pWNRZb44gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tg_de
2026-07-27 20:47:04
(15 hours ago)
44 attempts since 27.07.2026 22:46:10 CEST - last search for: /___proxy_subdomain_whm/login/
Web App Attack
Anonymous
2026-07-27 20:22:03
(15 hours ago)
Port Scan
Port Scan
๐จ๐ฟ
rawnullbyte
2026-07-27 20:22:01
(15 hours ago)
๐จ Honeypot triggered! ๐ฅ๏ธ System: NPot ๐ฏ Target: Unknown ๐ฃ๏ธ Path: /___proxy_subdomain_whm/login/ ๐ค At ...
show more
๐จ Honeypot triggered! ๐ฅ๏ธ System: NPot ๐ฏ Target: Unknown ๐ฃ๏ธ Path: /___proxy_subdomain_whm/login/ ๐ค Attacker IP: 52.238.24.38 โฐ Time: 2026-07-27 20:22:00 ๐ก User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0
show less
Web App Attack
๐บ๐ธ
Carltonfsck
2026-07-27 20:05:09
(15 hours ago)
52.238.24.38 - - [27/Jul/2026:20:05:08 +0000] "GET /.git/HEAD HTTP/1.1" 404 49
52.238.24.38 - - [27/ ...
show more
52.238.24.38 - - [27/Jul/2026:20:05:08 +0000] "GET /.git/HEAD HTTP/1.1" 404 49
52.238.24.38 - - [27/Jul/2026:20:05:08 +0000] "GET /.git/config HTTP/1.1" 404 49
52.238.24.38 - - [27/Jul/2026:20:05:08 +0000] "GET /.git/refs/heads/master HTTP/1.1" 404 49
...
show less
Hacking
Web App Attack