🇵🇱
Budyn
2026-09-05 16:24:13
(9 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: backup.teddypot.pro | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-05 07:25:09
(18 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cloud.budyn.ovh | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-01 23:55:04
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-08-29 09:17:26
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: shop.astropot.online | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-08-29 00:29:18
(1 week ago)
Try to access /xmlrpc.php
Web App Attack
🇵🇱
Budyn
2026-08-25 15:46:35
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: gitlab.definitelynotahoneypot.top | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-08-22 07:11:47
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after repeated server-error fuzzing. Eviden ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after repeated server-error fuzzing. Evidence: Repeated Server Errors (500)
show less
Hacking
Exploited Host
Web App Attack
🇵🇱
Budyn
2026-08-11 16:53:53
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.teddypot.site | URI: /xmlrpc.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-07-23 22:13:51
(1 month ago)
Try to access /xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-07-21 08:10:29
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 104.164.173.85 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.164.173.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 04:10:23.057012 2026] [security2:error] [pid 17385:tid 17385] [client 104.164.173.85:25998] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||koswerks.net|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "koswerks.net"] [uri "/index.bak"] [unique_id "al8pb0q43kENa8M8nq8hFgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
dispensight
2026-07-03 01:16:00
(2 months ago)
SecureLeaf CTI: recon path (ngrok-tagged). 2 req against help.dispensight.cloud (e.g. /admin). Defen ...
show more
SecureLeaf CTI: recon path (ngrok-tagged). 2 req against help.dispensight.cloud (e.g. /admin). Defensive report; verified infra.
show less
Port Scan
🇮🇹
VHosting
2026-06-28 13:30:07
(2 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇩🇪
Jarda_H
2026-06-09 06:46:23
(2 months ago)
http-crawl-non_statics
Web App Attack
🇩🇪
YF
2026-06-06 21:05:51
(2 months ago)
WordPress directory enumeration
Web App Attack
🇩🇪
FeG Deutschland
2026-06-03 23:32:33
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2468
Exploited Host
Web App Attack