๐ซ๐ฎ
NoaQT
2026-08-13 09:38:07
(3 days ago)
2026-08-13T09:38:06.599772+00:00 ingress-1 haproxy[16887]: 147.45.60.124:37052 [13/Aug/2026:09:20:52 ...
show more
2026-08-13T09:38:06.599772+00:00 ingress-1 haproxy[16887]: 147.45.60.124:37052 [13/Aug/2026:09:20:52.768] https_in~ https_in/<NOSRV> 386/-1/-1/-1/1021717 429 225 - - PR-- 415/411/0/0/0 0/0 "GET https://vault.mentis.si/ HTTP/2.0"
2026-08-13T09:38:06.599780+00:00 ingress-1 haproxy[16887]: 147.45.60.124:37052 [13/Aug/2026:09:20:52.768] https_in~ https_in/<NOSRV> 386/-1/-1/-1/1021717 429 225 - - PR-- 415/411/0/0/0 0/0 "GET https://vault.mentis.si/ HTTP/2.0"
2026-08-13T09:38:06.599789+00:00 ingress-1 haproxy[16887]: 147.45.60.124:37052 [13/Aug/2026:09:20:52.768] https_in~ https_in/<NOSRV> 386/-1/-1/-1/1021717 429 225 - - PR-- 415/411/0/0/0 0/0 "GET https://vault.mentis.si/ HTTP/2.0"
2026-08-13T09:38:06.599796+00:00 ingress-1 haproxy[16887]: 147.45.60.124:37052 [13/Aug/2026:09:20:52.768] https_in~ https_in/<NOSRV> 386/-1/-1/-1/1021717 429 225 - - PR-- 415/411/0/0/0 0/0 "GET https://vault.mentis.si/ HTTP/2.0"
2026-08-13T09:38:06.599804+00:00 ingress-1 haproxy[16887]: 147.45.60.124:37052 [13/A
...
show less
DDoS Attack
๐ฎ๐ฉ
sockominfo
2026-08-08 21:00:53
(1 week ago)
Zimbra: Login failures from malicious IP: 147.45.60.124. Threat Score: 6.3/10 (MEDIUM). Confidence: ...
show more
Zimbra: Login failures from malicious IP: 147.45.60.124. Threat Score: 6.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-08 20:00:09
(1 week ago)
Zimbra: Login failures from malicious IP: 147.45.60.124. Threat Score: 6/10 (MEDIUM). Reported by Ta ...
show more
Zimbra: Login failures from malicious IP: 147.45.60.124. Threat Score: 6/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฉ๐ช
anycast_ac
2026-08-07 20:04:27
(1 week ago)
[DDoS Attacker] This IP was attacking website as219123.guru and sent 100 requests on port 443
DDoS Attack
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2026-08-05 01:47:14
(1 week ago)
Aug 5 03:47:13 ksol dovecot[83114]: auth-worker(95965): conn unix:auth-worker (uid=143): auth-worke ...
show more
Aug 5 03:47:13 ksol dovecot[83114]: auth-worker(95965): conn unix:auth-worker (uid=143): auth-worker<5>: sql(anonymized@email,147.45.60.124,<kEhP80JYthaTLTx8>): unknown user (given password: I-AM-A-SUCKER-USING-A-WRONG-PASSWORD)
...
show less
Brute-Force
๐ฎ๐ฉ
sockominfo
2026-08-04 00:00:52
(1 week ago)
Zimbra: Login failures from malicious IP: 147.45.60.124. Threat Score: 6.3/10 (MEDIUM). Confidence: ...
show more
Zimbra: Login failures from malicious IP: 147.45.60.124. Threat Score: 6.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-03 23:00:09
(1 week ago)
Zimbra: Login failures from malicious IP: 147.45.60.124. Threat Score: 5.4/10 (MEDIUM). Reported by ...
show more
Zimbra: Login failures from malicious IP: 147.45.60.124. Threat Score: 5.4/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 05:16:27
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 147.45.60.124 (23052.ip-ptr.tech): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 147.45.60.124 (23052.ip-ptr.tech): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 01:16:19.470123 2026] [security2:error] [pid 1178144:tid 1178144] [client 147.45.60.124:50285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arzoma.com"] [uri "/.env"] [unique_id "amWYI4yJpA6YPHR1hVbpQwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 13:29:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 147.45.60.124 (23052.ip-ptr.tech): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 147.45.60.124 (23052.ip-ptr.tech): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:29:50.412951 2026] [security2:error] [pid 18535:tid 18535] [client 147.45.60.124:39953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amosellistonfortheladies.com"] [uri "/.env"] [unique_id "amS6TtGLEZPJA12aZ7QSvAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 09:17:45
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 147.45.60.124 (23052.ip-ptr.tech): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 147.45.60.124 (23052.ip-ptr.tech): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 05:17:40.597582 2026] [security2:error] [pid 1384184:tid 1384184] [client 147.45.60.124:56028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aquanauticsige.com"] [uri "/.env"] [unique_id "amR_NMeX-aINGul4Zeff9QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
MatStef132
2026-07-24 17:43:04
(3 weeks ago)
MatShield L7: blocked on mathost.eu (secret-path-probe)
DDoS Attack
Anonymous
2026-07-23 13:15:19
(3 weeks ago)
RdpGuard detected brute-force attempt on IMAP
Brute-Force
๐ฉ๐ช
anycast_ac
2026-07-22 18:02:21
(3 weeks ago)
[mirai-detector honeypot] Inbound attack against our honeypot on tcp/4145 (socks).
Family fingerprin ...
show more
[mirai-detector honeypot] Inbound attack against our honeypot on tcp/4145 (socks).
Family fingerprint: proxy-scanner
Commands captured:
$ socks4a CONNECT -> oracle.vanhoang.id.vn:18453
show less
DDoS Attack
๐ซ๐ท
MatStef132
2026-07-21 13:37:46
(3 weeks ago)
MatShield L7: blocked on mathost.eu (path-flood-burst)
DDoS Attack
๐ซ๐ท
MatStef132
2026-07-20 10:40:31
(3 weeks ago)
MatShield L7: blocked on mathost.eu (ua-quarantined)
Bad Web Bot