|
๐ฒ๐ฝ
148.235.162.50
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:58:44 UTC
Log evidence:
07/22/2026-10:58:43.597637 [**] [1:2010935:3] ET SCAN Suspicious inbound to MSSQL port 1433 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 148.235.162.50:53451 -> 185.127.18.66:1433
show less
|
Port Scan
Brute-Force
|
|
๐บ๐ธ
172.69.71.11
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:55:39 UTC
Log evidence:
07/22/2026-10:55:38.269278 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 172.69.71.11:13283 -> 185.127.18.66:8443
show less
|
Port Scan
Brute-Force
|
|
๐บ๐ธ
23.239.29.33
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:45:49 UTC
Log evidence:
07/22/2026-10:45:48.107215 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 23.239.29.33:52771 -> 185.127.18.66:8443
show less
|
Port Scan
Brute-Force
|
|
๐บ๐ธ
158.94.211.59
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:40:53 UTC
Log evidence:
07/22/2026-10:40:52.543347 [**] [1:2400026:4510] ET DROP Spamhaus DROP Listed Traffic Inbound group 27 [**] [Classification: Misc Attack] [Priority: 2] {TCP} 158.94.211.59:62574 -> 185.127.18.66:25
show less
|
Port Scan
Brute-Force
|
|
๐ฒ๐ฝ
187.226.97.81
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:30:34 UTC
Log evidence:
07/22/2026-10:30:33.967690 [**] [1:2010935:3] ET SCAN Suspicious inbound to MSSQL port 1433 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 187.226.97.81:51014 -> 185.127.18.66:1433
show less
|
Port Scan
Brute-Force
|
|
๐บ๐ธ
65.87.7.173
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:28:51 UTC
Log evidence:
07/22/2026-10:28:50.539435 [**] [1:2012296:2] ET VOIP Modified Sipvicious Asterisk PBX User-Agent [**] [Classification: Attempted Information Leak] [Priority: 2] {UDP} 65.87.7.173:60157 -> 185.127.18.66:5060
show less
|
Port Scan
Brute-Force
|
|
๐ฉ๐ช
130.12.180.174
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:26:17 UTC
Log evidence:
07/22/2026-10:26:16.417724 [**] [1:1000090:1] POLICY Unauthorized Management Port Access [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 130.12.180.174:41749 -> 185.127.18.66:22
show less
|
Port Scan
Brute-Force
|
|
๐ญ๐ฐ
104.28.163.51
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:25:56 UTC
Log evidence:
07/22/2026-10:25:55.897149 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 104.28.163.51:32885 -> 185.127.18.66:3003
show less
|
Port Scan
Brute-Force
|
|
๐ฑ๐น
141.98.9.111
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 10:24:08 UTC
Log evidence:
07/22/2026-10:24:07.730223 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 141.98.9.111:49211 -> 185.127.18.66:3389
show less
|
Port Scan
Brute-Force
|
|
๐บ๐ธ
162.158.167.130
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:55:04 UTC
Log evidence:
07/22/2026-09:55:03.097413 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 162.158.167.130:9895 -> 185.127.18.66:2086
07/22/2026-09:55:04.122392 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 162.158.167.130:9895 -> 185.127.18.66:2086
show less
|
Port Scan
Brute-Force
|
|
๐ฉ๐ช
69.5.169.59
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:54:28 UTC
Log evidence:
07/22/2026-09:54:27.016893 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 69.5.169.59:57480 -> 185.127.18.66:9000
show less
|
Port Scan
Brute-Force
|
|
๐บ๐ธ
159.203.82.128
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:50:55 UTC
Log evidence:
07/22/2026-09:50:53.820150 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 159.203.82.128:64660 -> 185.127.18.66:8080
show less
|
Port Scan
Brute-Force
|
|
๐ฏ๐ต
157.101.172.23
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:45:44 UTC
Log evidence:
07/22/2026-09:45:43.116646 [wDrop] [**] [1:7001101:1] FINSERV CRITICAL: Telnet Access Blocked [**] [Classification: Potential Corporate Privacy Violation] [Priority: 1] {TCP} 157.101.172.23:48118 -> 185.127.18.66:23
07/22/2026-09:45:43.116646 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 157.101.172.23:48118 -> 185.127.18.66:23
show less
|
Port Scan
Brute-Force
|
|
๐ฏ๐ต
8.211.173.155
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:45:14 UTC
Log evidence:
07/22/2026-09:45:13.506669 [**] [1:2010936:3] ET SCAN Suspicious inbound to Oracle SQL port 1521 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 8.211.173.155:16967 -> 185.127.18.66:1521
show less
|
Port Scan
Brute-Force
|
|
๐ธ๐ฌ
47.236.169.75
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:39:21 UTC
Log evidence:
07/22/2026-09:39:19.448143 [wDrop] [**] [1:7001102:1] FINSERV CRITICAL: FTP Access Warning [**] [Classification: Potential Corporate Privacy Violation] [Priority: 1] {TCP} 47.236.169.75:46870 -> 185.127.18.66:21
07/22/2026-09:39:19.448143 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 47.236.169.75:46870 -> 185.127.18.66:21
show less
|
Port Scan
Brute-Force
|
|
๐ณ๐ฑ
89.124.83.233
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:31:19 UTC
Log evidence:
89.124.83.233 - - [22/Jul/2026:09:31:17 +0100] "GET / HTTP/1.1" 200 409 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Async-Queue-Scanner/8.0"
07/22/2026-09:31:18.525520 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 89.124.83.233:50891 -> 185.127.18.66:2222
07/22/2026-09:31:18.525520 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 89.124.83.233:50891 -> 185.127.18.66:2222
show less
|
Port Scan
Brute-Force
|
|
๐ญ๐ฐ
101.32.49.171
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:26:22 UTC
Log evidence:
07/22/2026-09:26:21.702651 [**] [1:2221035:1] SURICATA HTTP Request excessive header repetition [**] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 101.32.49.171:45640 -> 185.127.18.66:80
show less
|
Port Scan
Brute-Force
|
|
๐ฎ๐ฉ
140.213.177.157
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:10:33 UTC
Log evidence:
07/22/2026-09:10:32.164520 [**] [1:2010935:3] ET SCAN Suspicious inbound to MSSQL port 1433 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 140.213.177.157:50866 -> 185.127.18.66:1433
show less
|
Port Scan
Brute-Force
|
|
๐ง๐ช
35.241.197.114
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 09:00:19 UTC
Log evidence:
07/22/2026-09:00:18.384126 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 35.241.197.114:46177 -> 185.127.18.66:3389
show less
|
Port Scan
Brute-Force
|
|
๐ง๐ช
34.38.255.11
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 08:56:33 UTC
Log evidence:
07/22/2026-08:56:32.120648 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 34.38.255.11:46125 -> 185.127.18.66:143
show less
|
Port Scan
Brute-Force
|
|
๐จ๐ณ
120.237.209.14
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 08:54:25 UTC
Log evidence:
07/22/2026-08:54:24.941161 [**] [1:2010935:3] ET SCAN Suspicious inbound to MSSQL port 1433 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 120.237.209.14:62095 -> 185.127.18.66:1433
show less
|
Port Scan
Brute-Force
|
|
๐ธ๐ฌ
172.70.189.58
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 08:51:09 UTC
Log evidence:
172.70.189.58 - - [22/Jul/2026:08:51:07 +0100] "GET /license.txt HTTP/1.1" 404 118 "-" "python-requests/2.27.1"
07/22/2026-08:51:08.043195 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.70.189.58:10882 -> 185.127.18.66:80
07/22/2026-08:51:08.043195 [**] [1:2017515:8] ET INFO User-Agent (python-requests) Inbound to Webserver [**] [Classification: Misc activity] [Priority: 3] {TCP} 172.70.189.58:10882 -> 185.127.18.66:80
show less
|
Port Scan
Brute-Force
|
|
๐ฎ๐ฉ
36.68.34.77
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 08:49:42 UTC
Log evidence:
07/22/2026-08:49:41.139926 [**] [1:2010935:3] ET SCAN Suspicious inbound to MSSQL port 1433 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 36.68.34.77:51191 -> 185.127.18.66:1433
show less
|
Port Scan
Brute-Force
|
|
๐ฎ๐ณ
103.160.49.83
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 08:34:29 UTC
Log evidence:
07/22/2026-08:34:28.315554 [**] [1:2010935:3] ET SCAN Suspicious inbound to MSSQL port 1433 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 103.160.49.83:10400 -> 185.127.18.66:1433
show less
|
Port Scan
Brute-Force
|
|
๐ณ๐ฑ
34.7.158.166
|
|
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-22 08:33:00 UTC
Log evidence:
07/22/2026-08:32:59.407716 [**] [1:1000090:1] POLICY Unauthorized Management Port Access [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 34.7.158.166:45432 -> 185.127.18.66:27017
07/22/2026-08:32:59.407716 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 34.7.158.166:45432 -> 185.127.18.66:27017
show less
|
Port Scan
Brute-Force
|