๐ฎ๐น
VHosting
2026-09-01 09:55:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-01 09:44:29
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: registry.astropot.tech | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-20 08:55:09
(1 week ago)
Try to access /xmlrpc.php
Web App Attack
๐ต๐ฑ
Budyn
2026-08-16 05:43:42
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: app.dont-eat-the-pudding.xyz | URI: /xmlrpc.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-12 04:17:48
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: db.budyn.ovh | URI: /xmlrpc.php | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-12 00:45:45
(3 weeks ago)
Try to access /xmlrpc.php
Web App Attack
๐ต๐ฑ
Budyn
2026-08-10 03:25:25
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: panel.dont-eat-the-pudding.top | URI: /xmlrpc.php | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-08 17:49:26
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.teddypot.store | URI: /xmlrpc.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-30 02:45:04
(1 month ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-07-27 10:21:33
(1 month ago)
This IP was detected by CrowdSec triggering custom/http-honeypot-path
Web App Attack
Bad Web Bot
๐ฏ๐ต
Kinsei Engineering Inc.
2026-07-24 03:18:12
(1 month ago)
nginx:Illicit login attempts to the CMS, or investigation into CMS plugins with vulnerabilities.
Brute-Force
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 10:04:55
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 104.164.126.154 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 104.164.126.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 06:04:47.694006 2026] [security2:error] [pid 26414:tid 26414] [client 104.164.126.154:8132] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||keystroke.info|F|2"] [data ".php.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "keystroke.info"] [uri "/LocalSettings.php.backup"] [unique_id "aldbP5njr7Faf8NKNF7AcwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-11 20:02:19
(1 month ago)
Web attack
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-07-06 06:30:03
(1 month ago)
2026/07/06 06:30:02 [error] 1576696#1576696: *147476 connect() failed (111: Connection refused) whil ...
show more
2026/07/06 06:30:02 [error] 1576696#1576696: *147476 connect() failed (111: Connection refused) while connecting to upstream, client: 104.164.126.154, server: wynnesmiles.bridginggaps.tech, request: "GET / HTTP/1.1", upstream: "http://127.0.0.1:4000/", host: "wynnesmiles.bridginggaps.tech"
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-06-19 08:00:05
(2 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack