๐ช๐ธ
77.224.189.254
5 minutes ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐ญ๐ฐ
20.239.141.177
52 minutes ago
Detectors: [NGINX] | Reasons: Targeting a decommissioned/expired domain name (historical data recon) ...
show more
Detectors: [NGINX] | Reasons: Targeting a decommissioned/expired domain name (historical data recon) | Evidence: High-Criminality-Signature (p0f:*:128:0:*:65535,8:mss,nop,ws,nop,nop,sok:df,id+:0 - Ratio:0.96) | TCP Fingerprint: Modern Windows (Link:IPIP or SIT, Uptime:0m)
show less
Bad Web Bot
Web App Attack
๐ฎ๐ท
185.112.33.84
1 hour ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 1)
show less
Port Scan
๐จ๐ฆ
192.53.122.11
1 hour ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Persistent-Slow-Scanner (Strikes: 7), Repeat-Offender (Past Bans: 6)
show less
Port Scan
๐ฉ๐ช
34.107.36.160
2 hours ago
Detectors: [SURICATA, NGINX] | Reasons: Automated scan targeting an unauthorized host or default ser ...
show more
Detectors: [SURICATA, NGINX] | Reasons: Automated scan targeting an unauthorized host or default server sinkhole | Suricata: Web Server attack | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:0m)
show less
Web App Attack
Hacking
Port Scan
Bad Web Bot
๐ง๐ท
45.4.56.29
2 hours ago
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-C ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-Criminality-Signature (p0f:*:255:0:*:1024,0:mss::0 - Ratio:0.92), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:PPPoE, Uptime:0m)
show less
Hacking
Web App Attack
๐บ๐ธ
44.235.74.14
2 hours ago
Detectors: [NGINX] | Reasons: Targeting a decommissioned/expired domain name (historical data recon) ...
show more
Detectors: [NGINX] | Reasons: Targeting a decommissioned/expired domain name (historical data recon) | Evidence: High-Criminality-Signature (ja4:t13d2512h1 - Ratio:0.98) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:PPPoE, Uptime:27748m)
show less
Bad Web Bot
Web App Attack
๐ท๐ช
102.35.147.195
2 hours ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 2)
show less
Port Scan
๐บ๐ธ
34.222.179.168
3 hours ago
Detectors: [CROWDSEC, NGINX] | Reasons: Targeting a decommissioned/expired domain name (historical d ...
show more
Detectors: [CROWDSEC, NGINX] | Reasons: Targeting a decommissioned/expired domain name (historical data recon) | CrowdSec: Reconnaissance scan | Evidence: High-Criminality-Signature (ja4:t13d2512h1 - Ratio:0.98) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:PPPoE, Uptime:54538m)
show less
Port Scan
Web App Attack
Bad Web Bot
๐ง๐ฉ
119.148.3.101
3 hours ago
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: Verified-Bot ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: Verified-Bot-JA4-Match (t13d201200), High-Criminality-Signature (ja4:t13d201200 - Ratio:0.99), High-Criminality-Signature (p0f:*:128:0:*:65535,8:mss,nop,ws,nop,nop,sok:df,id+:0 - Ratio:0.96), OS-Signature-Mismatch (UA:Linux/p0f:Windows) | UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/99.0.0.0 Safari/537.36 | TCP Fingerprint: Modern Windows (Link:Unknown, Uptime:0m)
show less
Port Scan
Web App Attack
๐ง๐ท
200.189.73.217
3 hours ago
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: Verified-Bot ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: Verified-Bot-JA4-Match (t13d201200), High-Criminality-Signature (ja4:t13d201200 - Ratio:0.99), High-Criminality-Signature (p0f:*:128:0:*:65535,8:mss,nop,ws,nop,nop,sok:df,id+:0 - Ratio:0.96) | UA: Mozilla/5.0 (Windows NT 6.2; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/85.0.0.0 Safari/537.36 | TCP Fingerprint: Modern Windows (Link:IPIP or SIT, Uptime:0m)
show less
Port Scan
Web App Attack
๐ฏ๐ต
20.210.186.186
3 hours ago
Detectors: [CROWDSEC, NGINX] | Reasons: CrowdSec: Security alert | Automated scan targeting an unaut ...
show more
Detectors: [CROWDSEC, NGINX] | Reasons: CrowdSec: Security alert | Automated scan targeting an unauthorized host or default server sinkhole | Evidence: Persistent-Slow-Scanner (Strikes: 4), High-Criminality-Signature (p0f:*:128:0:*:65535,8:mss,nop,ws,nop,nop,sok:df,id+:0 - Ratio:0.96), Repeat-Offender (Past Bans: 3) | TCP Fingerprint: Modern Windows (Link:IPIP or SIT, Uptime:0m)
show less
Port Scan
Bad Web Bot
Web App Attack
๐จ๐ณ
39.104.64.139
3 hours ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Persistent-Slow-Scanner (Strikes: 5), Repeat-Offender (Past Bans: 4)
show less
Port Scan
๐จ๐ณ
139.199.157.165
4 hours ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐บ๐ธ
32.185.195.97
4 hours ago
Detectors: [CROWDSEC, NGINX] | Reasons: Automated scan targeting an unauthorized host or default ser ...
show more
Detectors: [CROWDSEC, NGINX] | Reasons: Automated scan targeting an unauthorized host or default server sinkhole | CrowdSec: Reconnaissance scan | Evidence: URL-Found-In-UA, High-Criminality-Signature (ja4:t13d2512h1 - Ratio:0.98), High-Criminality-Signature (ja4h:5284a4e8dcdc8b18d4c888678c3ea4b3 - Ratio:0.97) | UA: Mozilla/5.0 (compatible; wpbot/1.4; +https://forms.gle/ajBaxygz9jSR8p8G9) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:PPPoE, Uptime:6686m)
show less
Port Scan
Bad Web Bot
Web App Attack
๐ง๐ท
2804:d41:a1e2:5e00:9132:c467:3451:d3a9
4 hours ago
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: URL-Found-In ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: URL-Found-In-UA, High-Criminality-Signature (ja4:t12d190800 - Ratio:0.99), High-Criminality-Signature (p0f:*:64:0:*:mss*45,8:mss,nop,ws,nop,nop,sok:flow:0 - Ratio:0.97) | UA: WordPress.com; https://wordpress.com | TCP Fingerprint: Unknown (Link:PPPoE, Uptime:0m)
show less
Port Scan
Web App Attack
๐ฟ๐ฆ
168.210.214.29
4 hours ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 1)
show less
Port Scan
๐ธ๐ช
178.78.193.230
4 hours ago
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: Verified-Bot ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: Verified-Bot-JA4-Match (t13d201200), High-Criminality-Signature (ja4:t13d201200 - Ratio:0.99), High-Criminality-Signature (p0f:*:128:0:*:65535,8:mss,nop,ws,nop,nop,sok:df,id+:0 - Ratio:0.96) | UA: Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/95.0.0.0 Safari/537.36 | TCP Fingerprint: Modern Windows (Link:PPPoE, Uptime:0m)
show less
Port Scan
Web App Attack
๐บ๐ฆ
195.18.19.30
5 hours ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐จ๐ณ
120.48.50.133
5 hours ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 1)
show less
Port Scan
๐ฆ๐บ
20.92.239.62
5 hours ago
Detectors: [NGINX] | Reasons: Targeting a decommissioned/expired domain name (historical data recon) ...
show more
Detectors: [NGINX] | Reasons: Targeting a decommissioned/expired domain name (historical data recon) | Evidence: High-Criminality-Signature (p0f:*:128:0:*:65535,8:mss,nop,ws,nop,nop,sok:df,id+:0 - Ratio:0.96), Repeat-Offender (Past Bans: 1) | TCP Fingerprint: Modern Windows (Link:IPIP or SIT, Uptime:0m)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
136.116.155.64
6 hours ago
Detectors: [NGINX] | Reasons: bad_user_agent | Evidence: URL-Found-In-UA, High-Criminality-Signature ...
show more
Detectors: [NGINX] | Reasons: bad_user_agent | Evidence: URL-Found-In-UA, High-Criminality-Signature (p0f:*:128:0:*:mss*46,8:mss,nop,ws,nop,nop,sok:df,id+,ecn:0 - Ratio:0.99) | UA: Mozilla/5.0 (compatible; CMS-Checker/1.0; +https://example.com) | TCP Fingerprint: Legacy Windows (XP/2003) (Link:generic tunnel or VPN, Uptime:0m)
show less
Port Scan
๐บ๐ธ
100.28.191.174
6 hours ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐ณ๐ฑ
194.36.190.246
6 hours ago
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Persistent-Slow-Scanner (Strikes: 4), Repeat-Offender (Past Bans: 3)
show less
Port Scan
๐ญ๐ฐ
40.83.95.41
6 hours ago
Detectors: [CROWDSEC] | Reasons: CrowdSec: Security alert | Evidence: Persistent-Slow-Scanner (Strik ...
show more
Detectors: [CROWDSEC] | Reasons: CrowdSec: Security alert | Evidence: Persistent-Slow-Scanner (Strikes: 5), High-Criminality-Signature (p0f:*:128:0:*:65535,8:mss,nop,ws,nop,nop,sok:df,id+:0 - Ratio:0.96), Repeat-Offender (Past Bans: 4) | TCP Fingerprint: Modern Windows (Link:IPIP or SIT, Uptime:0m)
show less
Web App Attack