|
๐จ๐ณ
118.145.104.105
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 1)
show less
|
Port Scan
|
|
๐จ๐ฆ
35.203.68.180
|
|
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-C ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-Criminality-Signature (ja4:t13d1011h1 - Ratio:0.96), High-Criminality-Signature (ja4h:5cf9f33397d2cfab2c8ca2fd9e424522 - Ratio:0.96) | UA: crusader-worker/1.0 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:25538m)
show less
|
Hacking
Web App Attack
|
|
๐ฉ๐ช
85.14.245.122
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Persistent-Slow-Scanner (Strikes: 384), Repeat-Offender (Past Bans: 383)
show less
|
Port Scan
|
|
๐บ๐ธ
8.234.217.180
|
|
Detectors: [NGINX] | Reasons: bad_user_agent | Evidence: URL-Found-In-UA, High-Criminality-Signature ...
show more
Detectors: [NGINX] | Reasons: bad_user_agent | Evidence: URL-Found-In-UA, High-Criminality-Signature (p0f:*:128:0:*:mss*46,8:mss,nop,ws,nop,nop,sok:df,id+,ecn:0 - Ratio:0.99) | UA: Mozilla/5.0 (compatible; CMS-Checker/1.0; +https://example.com) | TCP Fingerprint: Legacy Windows (XP/2003) (Link:generic tunnel or VPN, Uptime:0m)
show less
|
Port Scan
|
|
๐ซ๐ฎ
77.42.49.249
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 1)
show less
|
Port Scan
|
|
๐บ๐ธ
20.3.231.118
|
|
Detectors: [NGINX, SURICATA] | Reasons: Suricata: IDS security alert | Nginx Honeypot: Sensitive con ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Suricata: IDS security alert | Nginx Honeypot: Sensitive configuration file search | Evidence: High-Criminality-Signature (p0f:*:64:0:*:mss*44,10:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.89), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:IPIP or SIT, Uptime:31459m)
show less
|
Hacking
Web App Attack
|
|
๐บ๐ธ
34.75.216.192
|
|
Detectors: [NGINX] | Reasons: Nginx Honeypot: Exploitation / Shell attempt | Evidence: High-Criminal ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Exploitation / Shell attempt | Evidence: High-Criminality-Signature (ja4:t13d1011h1 - Ratio:0.96), High-Criminality-Signature (ja4h:5cf9f33397d2cfab2c8ca2fd9e424522 - Ratio:0.95) | UA: crusader-worker/1.0 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:43259m)
show less
|
Hacking
|
|
๐จ๐ณ
106.63.26.141
|
|
Detectors: [NGINX] | Reasons: Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evid ...
show more
Detectors: [NGINX] | Reasons: Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evidence: Repeat-Offender (Past Bans: 2) | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:0m)
show less
|
Port Scan
|
|
๐บ๐ธ
35.227.123.157
|
|
Detectors: [NGINX, SURICATA] | Reasons: Nginx Honeypot: Sensitive configuration file search | Surica ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Nginx Honeypot: Sensitive configuration file search | Suricata: Web Server attack | Evidence: High-Criminality-Signature (ja4:t13d1011h1 - Ratio:0.96), High-Criminality-Signature (ja4h:5cf9f33397d2cfab2c8ca2fd9e424522 - Ratio:0.95) | UA: crusader-worker/1.0 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:30586m)
show less
|
Hacking
Web App Attack
|
|
๐ฆ๐ฒ
46.36.123.36
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐ท๐บ
95.31.168.194
|
|
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previ ...
show more
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previous ban | Evidence: High-Criminality-Signature (p0f:*:64:0:*:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.96), Repeat-Offender (Past Bans: 2) | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0 Safari/537.36 NWSIP-Stage1 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:PPPoE, Uptime:36958m)
show less
|
Port Scan
Web App Attack
|
|
๐จ๐ฒ
154.72.163.169
|
|
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: High-Crimina ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Administration interface scan | Evidence: High-Criminality-Signature (ja4:t12d190800 - Ratio:0.93) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/64.0.0.0 Safari/537.36 | TCP Fingerprint: Modern Windows (Link:PPPoE, Uptime:0m)
show less
|
Port Scan
Web App Attack
|
|
๐ณ๐ฑ
185.93.89.86
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐ฐ๐ช
102.0.28.22
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐บ๐ธ
34.139.22.117
|
|
Detectors: [NGINX, SURICATA] | Reasons: Nginx Honeypot: Sensitive configuration file search | Surica ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Nginx Honeypot: Sensitive configuration file search | Suricata: Web Server attack | Evidence: High-Criminality-Signature (ja4:t13d1011h1 - Ratio:0.96), High-Criminality-Signature (ja4h:5cf9f33397d2cfab2c8ca2fd9e424522 - Ratio:0.95) | UA: crusader-worker/1.0 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:3548m)
show less
|
Hacking
Web App Attack
|
|
๐ต๐ธ
188.161.159.76
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐ฆ๐ท
186.19.123.83
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐จ๐ณ
61.146.235.54
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐บ๐ธ
20.169.50.119
|
|
Detectors: [NGINX] | Reasons: bad_user_agent | Evidence: Known-Scanner-UA (Mozilla/5.0 zgrab/0.x), H ...
show more
Detectors: [NGINX] | Reasons: bad_user_agent | Evidence: Known-Scanner-UA (Mozilla/5.0 zgrab/0.x), High-Criminality-Signature (p0f:*:64:0:*:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.96), Repeat-Offender (Past Bans: 1) | UA: Mozilla/5.0 zgrab/0.x | TCP Fingerprint: Linux (Legacy/Embedded) (Link:IPIP or SIT, Uptime:0m)
show less
|
Port Scan
|
|
๐จ๐ณ
106.13.105.183
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐บ๐ธ
20.40.253.27
|
|
Detectors: [NGINX] | Reasons: bad_user_agent | Evidence: Known-Scanner-UA (Mozilla/5.0 zgrab/0.x), H ...
show more
Detectors: [NGINX] | Reasons: bad_user_agent | Evidence: Known-Scanner-UA (Mozilla/5.0 zgrab/0.x), High-Criminality-Signature (p0f:*:64:0:*:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.95) | UA: Mozilla/5.0 zgrab/0.x | TCP Fingerprint: Linux (Legacy/Embedded) (Link:IPIP or SIT, Uptime:0m)
show less
|
Port Scan
|
|
๐จ๐ณ
115.191.11.182
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐ท๐บ
77.74.177.114
|
|
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previ ...
show more
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previous ban | Evidence: Persistent-Slow-Scanner (Strikes: 4), High-Criminality-Signature (p0f:*:64:0:*:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.95), Repeat-Offender (Past Bans: 2) | UA: Mozilla/5.0 (Linux; arm_64; Android 12; CPH2205) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 YaBrowser/23.3.3.86.00 SA/3 Mobile Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:PPPoE, Uptime:0m)
show less
|
Port Scan
Web App Attack
|
|
๐บ๐ธ
18.215.151.183
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|
|
๐บ๐ธ
159.65.216.50
|
|
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
|
Port Scan
|