๐ต๐ฑ
sefinek.net
2026-04-11 16:20:35
(3 months ago)
Honeypot hit: Incoming HTTP traffic on port 81
Reported by: https://github.com/sefinek/T-Pot-To-Abus ...
show more
Honeypot hit: Incoming HTTP traffic on port 81
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Hacking
Bad Web Bot
๐ต๐ฑ
Roper123
2026-04-11 06:04:14
(3 months ago)
Web app exploits
Web App Attack
๐ต๐ฑ
wikdomain
2026-04-10 19:02:04
(3 months ago)
WEB Apache Struts 2 OGNL Script Injection -5.1 Attack at 2026-04-10T19:02:04+00:00, Source: 78.153.1 ...
show more
WEB Apache Struts 2 OGNL Script Injection -5.1 Attack at 2026-04-10T19:02:04+00:00, Source: 78.153.140.37, Destination: 192.168.1.52
show less
Brute-Force
๐ต๐ฑ
webadmin
2026-04-10 07:09:55
(3 months ago)
2026/04/10 09:09:44 [error] 1130916#1130916: *1198193 open() "/var/www/saisolutions.pl/json/setup-re ...
show more
2026/04/10 09:09:44 [error] 1130916#1130916: *1198193 open() "/var/www/saisolutions.pl/json/setup-restore.action" failed (2: No such file or directory), client: 78.153.140.37, server: saisolutions.pl, request: "GET /json/setup-restore.action HTTP/1.1", host: "saisolutions.pl", referrer: "http://195.116.29.52/json/setup-restore.action"
2026/04/10 09:09:49 [error] 1130916#1130916: *1198200 open() "/var/www/saisolutions.pl/template/aui/text-inline.vm" failed (2: No such file or directory), client: 78.153.140.37, server: saisolutions.pl, request: "GET /template/aui/text-inline.vm HTTP/1.1", host: "saisolutions.pl", referrer: "http://195.116.29.52/template/aui/text-inline.vm"
2026/04/10 09:09:54 [error] 1130916#1130916: *1198226 open() "/var/www/saisolutions.pl/pages/templates2/viewpagetemplate.action" failed (2: No such file or directory), client: 78.153.140.37, server: saisolutions.pl, request: "GET /pages/templates2/viewpagetemplate.action HTTP/1.1", host: "saisolutions.pl", referrer: "h
...
show less
Web App Attack
๐ต๐ฑ
rafamiga
2026-04-10 02:23:42
(3 months ago)
fail2ban/ufw - Port scan detected.
...
Port Scan
๐ต๐ฑ
derester
2026-04-09 02:06:10
(3 months ago)
Forwarded traffic flood detected by MikroTik (threshold: >100 new connections/s, burst 1)
DDoS Attack
๐ต๐ฑ
webadmin
2026-04-08 15:35:36
(3 months ago)
2026/04/08 17:35:34 [error] 1852599#1852599: *763014 open() "/usr/share/nginx/html/template/aui/text ...
show more
2026/04/08 17:35:34 [error] 1852599#1852599: *763014 open() "/usr/share/nginx/html/template/aui/text-inline.vm" failed (2: No such file or directory), client: 78.153.140.37, server: mail.ellanea.com, request: "POST /template/aui/text-inline.vm HTTP/1.1", host: "213.25.105.149"
2026/04/08 17:35:34 [error] 1852598#1852598: *763013 open() "/usr/share/nginx/html/json/setup-restore.action" failed (2: No such file or directory), client: 78.153.140.37, server: mail.agileskincare.org, request: "POST /json/setup-restore.action HTTP/1.1", host: "213.25.105.150"
2026/04/08 17:35:34 [error] 1852599#1852599: *763027 open() "/usr/share/nginx/html/json/setup-restore.action" failed (2: No such file or directory), client: 78.153.140.37, server: mail.ellanea.com, request: "POST /json/setup-restore.action HTTP/1.1", host: "213.25.105.149"
2026/04/08 17:35:35 [error] 1852598#1852598: *763028 open() "/usr/share/nginx/html/template/aui/text-inline.vm" failed (2: No such file or directory), client: 78.153.14
...
show less
Web App Attack
๐ต๐ฑ
tomkolp
2026-04-08 09:35:00
(3 months ago)
CrowdSec - Scenario: crowdsecurity/CVE-2023-22515. Duration: 4h.
Web App Attack
Hacking
๐ต๐ฑ
Jacqb
2026-03-25 05:51:45
(4 months ago)
[Wed Mar 25 06:45:24.531679 2026] [authz_core:error] [pid 105049] [client 78.153.140.37:45486] AH016 ...
show more
[Wed Mar 25 06:45:24.531679 2026] [authz_core:error] [pid 105049] [client 78.153.140.37:45486] AH01630: client denied by server configuration: /var/www/html/
[Wed Mar 25 06:51:31.022679 2026] [authz_core:error] [pid 105039] [client 78.153.140.37:53660] AH01630: client denied by server configuration: /var/www/html/json
[Wed Mar 25 06:51:32.012098 2026] [authz_core:error] [pid 105050] [client 78.153.140.37:53676] AH01630: client denied by server configuration: /var/www/html/template
[Wed Mar 25 06:51:45.018784 2026] [authz_core:error] [pid 105049] [client 78.153.140.37:55612] AH01630: client denied by server configuration: /var/www/html/pages
[Wed Mar 25 06:51:45.019278 2026] [authz_core:error] [pid 104230] [client 78.153.140.37:55622] AH01630: client denied by server configuration: /var/www/html/pages
...
show less
Brute-Force
Web App Attack
Bad Web Bot
๐ญ๐บ
whitehoodie
2026-03-24 16:56:13
(4 months ago)
AUTOMATED REPORT: Looking for /pages/createpage-entervariables.action
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
Jacqb
2026-03-24 15:02:22
(4 months ago)
[Tue Mar 24 15:57:50.186079 2026] [authz_core:error] [pid 97541] [client 78.153.140.37:44692] AH0163 ...
show more
[Tue Mar 24 15:57:50.186079 2026] [authz_core:error] [pid 97541] [client 78.153.140.37:44692] AH01630: client denied by server configuration: /var/www/html/
[Tue Mar 24 16:02:15.252393 2026] [authz_core:error] [pid 97519] [client 78.153.140.37:40072] AH01630: client denied by server configuration: /var/www/html/json
[Tue Mar 24 16:02:15.337988 2026] [authz_core:error] [pid 97517] [client 78.153.140.37:40088] AH01630: client denied by server configuration: /var/www/html/template
[Tue Mar 24 16:02:22.231241 2026] [authz_core:error] [pid 1228] [client 78.153.140.37:46642] AH01630: client denied by server configuration: /var/www/html/pages
[Tue Mar 24 16:02:22.236669 2026] [authz_core:error] [pid 97520] [client 78.153.140.37:46626] AH01630: client denied by server configuration: /var/www/html/confluence
...
show less
Brute-Force
Web App Attack
Bad Web Bot
๐ณ๐ฑ
vaddilyin
2026-03-24 12:13:43
(4 months ago)
{"ClientAddr":"78.153.140.37:52640","ClientHost":"78.153.140.37","ClientPort":"52640","ClientUsernam ...
show more
{"ClientAddr":"78.153.140.37:52640","ClientHost":"78.153.140.37","ClientPort":"52640","ClientUsername":"-","DownstreamContentSize":19,"DownstreamStatus":404,"Duration":42625,"GzipRatio":0,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":42625,"RequestAddr":"148.253.213.233","RequestContentSize":0,"RequestCount":106186,"RequestHost":"148.253.213.233","RequestMethod":"GET","RequestPath":"/setup/setupadministrator-start.action","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"StartLocal":"2026-03-24T12:13:38.303132454Z","StartUTC":"2026-03-24T12:13:38.303132454Z","TLSCipher":"TLS_CHACHA20_POLY1305_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-03-24T12:13:38Z"}
{"ClientAddr":"78.153.140.37:37534","ClientHost":"78.153.140.37","ClientPort":"37534","ClientUsername":"-","DownstreamContentSize":19,"DownstreamStatus":404,"Duration":35736,"GzipRatio":0,"OriginContentSize":0,"OriginDuration"
...
show less
Web App Attack
๐ต๐ฑ
Tankudoraiba
2026-03-23 21:12:14
(4 months ago)
Unauthorized connection attempts on ports 443|80
Port Scan
Bad Web Bot
๐ญ๐บ
kranem
2026-03-22 18:00:22
(4 months ago)
Triggered Cloudflare WAF from GB.
Action taken: BLOCK
ASN: 202306 (HOSTGLOBALPLUS-AS)
Protocol: HTTP ...
show more
Triggered Cloudflare WAF from GB.
Action taken: BLOCK
ASN: 202306 (HOSTGLOBALPLUS-AS)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-03-22T17:47:24Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36 Edge/15.15063
show less
Bad Web Bot
๐ต๐ฑ
swiszczu
2026-03-22 17:10:42
(4 months ago)
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
78.153.140.37 - - [2 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
78.153.140.37 - - [22/Mar/2026:18:10:37 +0100] "POST /template/aui/text-inline.vm HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.4.24" "-"
78.153.140.37 - - [22/Mar/2026:18:10:41 +0100] "POST /pages/createpage.action?spaceKey=myproj HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Windows NT 6.2; rv:139.0) Gecko/20100101 Firefox/139.0" "-"
78.153.140.37 - - [22/Mar/2026:18:10:41 +0100] "POST /wiki/pages/createpage-entervariables.action HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Windows NT 10.0; rv:139.0) Gecko/20100101 Firefox/139.0" "-"
78.153.140.37 - - [22/Mar/2026:18:10:41 +0100] "POST /confluence/pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Fe
show less
Hacking
Web App Attack