π³π±
45.142.193.246
13 Jan 2026
Attempted port scan
Port Scan
π©πͺ
130.12.180.122
13 Jan 2026
01/12/2026-16:28:52.221243 [Drop] [**] [1:2066027:3] ET WEB_SPECIFIC_APPS React Server Components R ...
show more
01/12/2026-16:28:52.221243 [Drop] [**] [1:2066027:3] ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182) [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 130.12.180.122:55582 -> 47.181.161.66:80
01/12/2026-16:28:52.221243 [Drop] [**] [1:2066197:1] ET HUNTING Javascript Prototype Pollution Attempt via __proto__ in HTTP Body [**] [Classification: access to a potentially vulnerable web application] [Priority: 2] {TCP} 130.12.180.122:55582 -> 47.181.161.66:80
01/12/2026-16:28:52.221243 [Drop] [**] [1:2066030:1] ET HUNTING Javascript Sandbox Escape via Global Object (process) [**] [Classification: Unknown Traffic] [Priority: 3] {TCP} 130.12.180.122:55582 -> 47.181.161.66:80
01/12/2026-16:28:52.221243 [**] [1:2060252:1] ET INFO Go-http-client User-Agent Observed Inbound [**] [Classification: Misc activity] [Priority: 3] {TCP} 130.12.180.122:55582 -> 47.181.161.66:80
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
217.154.38.135
13 Jan 2026
01/10/2026-17:54:43.134034 [**] [1:2011465:8] ET WEB_SERVER /bin/sh In URI Possible Shell Command E ...
show more
01/10/2026-17:54:43.134034 [**] [1:2011465:8] ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 217.154.38.135:44962 -> 47.181.161.66:80
01/10/2026-17:54:43.134034 [**] [1:2034125:5] ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2 [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 217.154.38.135:44962 -> 47.181.161.66:80
01/10/2026-17:54:43.333170 [**] [1:2403307:105800] ET CINS Active Threat Intelligence Poor Reputation IP group 8 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 8.219.84.110:61520 -> 47.181.161.65:2222
01/10/2026-17:54:43.428419 [**] [1:2403314:105800] ET CINS Active Threat Intelligence Poor Reputation IP group 15 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 18.191.204.116:44071 -> 47.181.161.67:1024
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
ππ°
114.111.54.188
13 Jan 2026
01/10/2026-17:16:31.904849 [**] [1:2011465:8] ET WEB_SERVER /bin/sh In URI Possible Shell Command E ...
show more
01/10/2026-17:16:31.904849 [**] [1:2011465:8] ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 114.111.54.188:38018 -> 47.181.161.66:80
01/10/2026-17:16:31.904849 [**] [1:2034125:5] ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2 [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 114.111.54.188:38018 -> 47.181.161.66:80
01/10/2026-17:16:32.242481 [**] [1:2011465:8] ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 114.111.54.188:43630 -> 47.181.161.66:80
01/10/2026-17:16:32.242481 [**] [1:2034173:3] ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 114.111.54.188:43630 -> 47.181.161.66:80
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
π³π±
193.142.147.209
13 Jan 2026
IC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182) ...
show more
IC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182) [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 193.142.147.209:31004 -> 47.181.161.66:80
01/10/2026-16:16:00.263653 [**] [1:2016683:3] ET WEB_SERVER WebShell Generic - wget http - POST [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 193.142.147.209:31004 -> 47.181.161.66:80
01/10/2026-16:16:00.263653 [**] [1:2052797:1] ET WEB_SERVER Possible bash shell piped to dev tcp Inbound to WebServer M3 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 193.142.147.209:31004 -> 47.181.161.66:80
01/10/2026-16:16:00.263653 [**] [1:2066197:1] ET HUNTING Javascript Prototype Pollution Attempt via __proto__ in HTTP Body [**] [Classification: access to a potentially vulnerable web application] [Priority: 2] {TCP} 193.142.147.209:31004 -> 47.181.161.66:80
show less
Hacking
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
π±πΉ
91.224.92.14
13 Jan 2026
01/12/2026
16:58:30 2 TCP Potentially Bad Traffic 91.224.92.14
54546 47.181.161.68
...
show more
01/12/2026
16:58:30 2 TCP Potentially Bad Traffic 91.224.92.14
54546 47.181.161.68
80 1:2016683
ET WEB_SERVER WebShell Generic - wget http - POST
show less
Bad Web Bot
Web App Attack
π§π¬
79.124.62.134
13 Jan 2026
01/12/2026
16:42:19 2 TCP Attempted Information Leak 79.124.62.134
44153 47.181.161.68 ...
show more
01/12/2026
16:42:19 2 TCP Attempted Information Leak 79.124.62.134
44153 47.181.161.68
62399 1:2009582
ET SCAN NMAP -sS window 1024
show less
Port Scan
π΅π±
194.180.49.115
13 Jan 2026
01/12/2026
16:41:13 2 TCP Attempted Information Leak 194.180.49.115
45307 47.181.161.6 ...
show more
01/12/2026
16:41:13 2 TCP Attempted Information Leak 194.180.49.115
45307 47.181.161.68
25782 1:2009582
ET SCAN NMAP -sS window 1024
show less
Port Scan
π·π΄
80.94.95.226
13 Jan 2026
01/12/2026
16:41:11 2 TCP Attempted Information Leak 80.94.95.226
44865 47.181.161.69
...
show more
01/12/2026
16:41:11 2 TCP Attempted Information Leak 80.94.95.226
44865 47.181.161.69
8443 1:2009582
show less
Port Scan
π©πͺ
213.209.159.181
13 Jan 2026
01/12/2026
16:40:23 2 TCP Attempted Information Leak 213.209.159.181
58118 47.181.161. ...
show more
01/12/2026
16:40:23 2 TCP Attempted Information Leak 213.209.159.181
58118 47.181.161.66
443 1:2009582
ET SCAN NMAP -sS window 1024
show less
Port Scan
π³π±
45.142.193.104
13 Jan 2026
01/12/2026
16:40:10 2 TCP Attempted Information Leak 45.142.193.104
43757 47.181.161.6 ...
show more
01/12/2026
16:40:10 2 TCP Attempted Information Leak 45.142.193.104
43757 47.181.161.67
45473 1:2009582
ET SCAN NMAP -sS window 1024
show less
Port Scan
π³π±
45.142.193.123
13 Jan 2026
01/12/2026
16:40:07 2 TCP Attempted Information Leak 45.142.193.123
41491 47.181.161.6 ...
show more
01/12/2026
16:40:07 2 TCP Attempted Information Leak 45.142.193.123
41491 47.181.161.68
41201 1:2009582
ET SCAN NMAP -sS window 1024
show less
Port Scan
π³π±
45.142.193.223
13 Jan 2026
01/12/2026
16:49:15 2 TCP Attempted Information Leak 45.142.193.223
43483 47.181.161.6 ...
show more
01/12/2026
16:49:15 2 TCP Attempted Information Leak 45.142.193.223
43483 47.181.161.69
44540 1:2009582
ET SCAN NMAP -sS window 1024
show less
Port Scan
π΅π±
109.205.211.115
13 Jan 2026
01/12/2026
16:48:40 2 TCP Attempted Information Leak 109.205.211.115
45244 47.181.161. ...
show more
01/12/2026
16:48:40 2 TCP Attempted Information Leak 109.205.211.115
45244 47.181.161.67
50193 1:2009582
ET SCAN NMAP -sS window 1024
show less
Port Scan
π©πͺ
87.120.166.0
09 Jan 2026
01/09/2026
15:38:44 1 TCP A Network Trojan was detected 87.120.166.0
49196 47.181.161. ...
show more
01/09/2026
15:38:44 1 TCP A Network Trojan was detected 87.120.166.0
49196 47.181.161.66
80 1:2019804
ET WEB_SERVER PHP.//Input in HTTP POST
01/09/2026
15:38:44 1 TCP A Network Trojan was detected 87.120.166.0
49196 47.181.161.66
80 1:2016982
ET WEB_SERVER auto_prepend_file PHP config option in uri
01/09/2026
15:38:44 1 TCP A Network Trojan was detected 87.120.166.0
49196 47.181.161.66
80 1:2016977
ET WEB_SERVER allow_url_include PHP config option in uri
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
π³π±
193.142.147.209
09 Jan 2026
01/09/2026
14:14:21 2 TCP Potentially Bad Traffic 193.142.147.209
55792 47.181.161.68
...
show more
01/09/2026
14:14:21 2 TCP Potentially Bad Traffic 193.142.147.209
55792 47.181.161.68
80 1:2016683
ET WEB_SERVER WebShell Generic - wget http - POST
show less
Bad Web Bot
Web App Attack
π©πͺ
130.12.180.57
09 Jan 2026
1 UDP Attempted Administrator Privilege Gain 130.12.180.57
56530 47.181.161.69
9 ...
show more
1 UDP Attempted Administrator Privilege Gain 130.12.180.57
56530 47.181.161.69
9034 1:2044008
ET EXPLOIT Realtek SDK - Command Execution/Backdoor Access Inbound (CVE-2021-35394)
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
π³π±
193.142.147.209
09 Jan 2026
01/09/2026
14:14:21 1 TCP Web Application Attack 193.142.147.209
55792 47.181.161.68
...
show more
01/09/2026
14:14:21 1 TCP Web Application Attack 193.142.147.209
55792 47.181.161.68
80 1:2066027
ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182)
show less
Hacking
Web App Attack
π³π±
193.142.146.230
08 Jan 2026
[Birdo Server] SSH-Multi login Attempt
Brute-Force
SSH
πΊπ¦
185.243.96.116
08 Jan 2026
[Birdo Server] SSH-Multi login Attempt
Brute-Force
SSH
π©πͺ
130.12.180.51
08 Jan 2026
[Birdo Server] SSH-Multi login Attempt
Brute-Force
SSH
π―π΅
47.74.0.222
08 Jan 2026
[Birdo Server] SSH-Multi login Attempt
Brute-Force
SSH
πΊπΈ
207.181.200.121
08 Jan 2026
[Birdo Server] SSH-Multi login Attempt
Brute-Force
SSH
π³π±
185.226.197.60
08 Jan 2026
[Birdo Server] SSH-Multi login Attempt
Brute-Force
SSH
π³π±
185.226.197.57
08 Jan 2026
[Birdo Server] SSH-Multi login Attempt
Brute-Force
SSH