๐ฌ๐ง
PeravixGroup
2026-05-08 08:22:28
(1 month ago)
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: ME ...
show more
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: MEDIUM. Aaran.cloud
show less
IoT Targeted
Brute-Force
๐บ๐ธ
donarev419
2026-05-08 04:35:38
(1 month ago)
Port scan detected on port 23 (connection without data transfer)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-04 03:50:44
(2 months ago)
(mod_security) mod_security (id:211030) triggered by 66.181.160.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211030) triggered by 66.181.160.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 23:50:34.951882 2026] [security2:error] [pid 30254:tid 30254] [client 66.181.160.1:29211] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at ARGS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "17"] [id "211030"] [rev "3"] [msg "COMODO WAF: LDAP Injection Attack||psdinnersready.com|F|2"] [data "Matched Data: ('~'||( found within ARGS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "psdinnersready.com"] [uri "/index.php"] [unique_id "adCKioCtMuPSnF6ImvDk6AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-05 03:10:07
(3 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-03-03 08:32:41
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 66.181.160.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 66.181.160.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 03:32:33.335065 2026] [security2:error] [pid 30898:tid 30898] [client 66.181.160.1:55257] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||batw.net|F|2"] [data ".borzois.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "batw.net"] [uri "/borzois.com/silkenswift/www.borzois.com"] [unique_id "aaacoYQz_Vm1ZQQ6yhUIUwAAAAA"], referer: https://batw.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-01-14 06:55:21
(5 months ago)
tcp/23
Port Scan
๐บ๐ธ
TPI-Abuse
2025-12-10 14:52:11
(6 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
Anonymous
2025-12-04 15:47:32
(6 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-11-22 11:28:46
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 66.181.160.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 66.181.160.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 06:28:34.349045 2025] [security2:error] [pid 13057:tid 13057] [client 66.181.160.1:31917] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogerheath.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogerheath.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aSGeYoZc0v_cgw6T_mH_bwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-21 12:22:40
(6 months ago)
scanning http requests from known botnet
Web App Attack
๐ฉ๐ช
Beta
2025-10-19 07:30:02
(7 months ago)
ports, 445/24H:1/7D:1
Port Scan
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-10-10 05:45:05
(8 months ago)
Port probe to tcp/445 (smb)
[srv136]
Port Scan
Hacking
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-09-22 10:08:31
(8 months ago)
2 port probes: 2x tcp/445 (smb)
[gda]
Port Scan
Hacking
Anonymous
2025-09-11 04:01:21
(9 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ณ๐ฑ
exxos
2025-09-01 19:03:01
(9 months ago)
Attacks with Bad user agents
Hacking