π΅π±
Budyn
2026-10-10 12:46:36
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: gitlab.teddypot.space | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-10-10 08:32:38
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: auth.teddypot.space | URI: /.htaccess | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
π΅π±
Budyn
2026-10-10 04:06:16
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cache.teddypot.website | URI: /.aws/credentials | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
πΊπΈ
Kurtbaby
2026-09-25 17:53:00
(2 weeks ago)
Brute-Force
Port Scan
Hacking
πΊπΈ
drewf.ink
2026-09-24 11:47:38
(2 weeks ago)
[11:47] Attempted HTTPS GlobalProtect login with credentials websh:w***h
Web App Attack
π¨πΏ
lp
2026-09-21 07:49:36
(2 weeks ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 104.207.45.235
2026-09-21T08:44:39+02 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 104.207.45.235
2026-09-21T08:44:39+02:00 vpn Access-Reject 'lkoeleman' station: 104.207.45.235 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π¨πΏ
lp
2026-09-04 06:21:12
(1 month ago)
Unauthorized VPN login attempts: 7 attempts were recorded from 104.207.45.235
2026-09-04T07:40:08+02 ...
show more
Unauthorized VPN login attempts: 7 attempts were recorded from 104.207.45.235
2026-09-04T07:40:08+02:00 vpn Access-Reject 'technogym' station: 104.207.45.235 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T07:41:51+02:00 vpn Access-Reject 'cad' station: 104.207.45.235 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T07:43:53+02:00 vpn Access-Reject 'helpdesk' station: 104.207.45.235 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T07:45:41+02:00 vpn Access-Reject 'rw' station: 104.207.45.235 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T07:47:42+02:00 vpn Access-Reject 'sekretariat' station: 104.207.45.235 auth-type: - realm: vse.cz nas: <
show less
Brute-Force
Web App Attack
πΈπͺ
OnTheEdge
2026-09-03 18:39:53
(1 month ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
πΊπΈ
drewf.ink
2026-09-02 02:48:07
(1 month ago)
[02:48] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[02:48] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
πΊπΈ
drewf.ink
2026-09-01 07:03:02
(1 month ago)
[07:03] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[07:03] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
π«π·
Sklurk
2026-07-25 10:34:37
(2 months ago)
Web App Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 05:06:08
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:06:04.180505 2026] [security2:error] [pid 2355468:tid 2355468] [client 104.207.45.235:61001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idonthaveawebpage.com"] [uri "/admin/.env"] [unique_id "aYq8vCwPFMkVhkC2CfnW0AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 04:18:24
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:18:19.154934 2026] [security2:error] [pid 18298:tid 18298] [client 104.207.45.235:11071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iclog.us"] [uri "/api/.env"] [unique_id "aYqxi9gmZpq2iKQzz7LA2gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 03:58:32
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:58:27.769167 2026] [security2:error] [pid 12745:tid 12768] [client 104.207.45.235:26971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kiwimagic.net"] [uri "/admin/.git/config"] [unique_id "aYqs4yzFaBOFmlrgLfF7hAAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-02-10 02:25:17
(8 months ago)
Blocking for trying to access an exploit file: /.env.staging
Hacking