๐ต๐ฑ
Budyn
2026-09-14 09:42:26
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: keycloak.teddypot.store | URI: /protected/.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฉ๐ช
Tamsy
2026-09-13 01:06:34
(3 days ago)
HTTPD - 4xx scan
Web App Attack
๐บ๐ธ
LotPhantom
2026-09-11 03:58:11
(5 days ago)
104.243.242.4 - - [11/Sep/2026:03:57:11 +0000] "GET /backend/.env HTTP/1.1" 404 146 "-" "Mozilla/5.0 ...
show more
104.243.242.4 - - [11/Sep/2026:03:57:11 +0000] "GET /backend/.env HTTP/1.1" 404 146 "-" "Mozilla/5.0 SecurityAuditor/2.0" "0"
...
show less
Web App Attack
๐ฉ๐ช
Teufel100
2026-09-10 10:38:45
(5 days ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-09-08 15:38:04
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: portal.sweetpuddingtrap.xyz | URI: /core/.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-09-08 04:22:19
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: portal.sweetpuddingtrap.xyz | URI: /secret/.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-07 19:43:23
(1 week ago)
Repeated 403 Forbidden responses
Web App Attack
๐ฉ๐ช
Reinhard
2026-09-07 10:37:52
(1 week ago)
Software package attack. /application/config/database.php
Web App Attack
๐ต๐ฑ
Budyn
2026-09-07 05:29:29
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: portal.teddypot.cloud | URI: /.env.example | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
notelseit
2026-09-02 04:08:23
(2 weeks ago)
2026-09-02T06:08:07.471523+02:00 mail dovecot: imap-login: Disconnected: Connection closed (no auth ...
show more
2026-09-02T06:08:07.471523+02:00 mail dovecot: imap-login: Disconnected: Connection closed (no auth attempts in 1 secs): user=<>, rip=104.243.242.4, lip=65.21.131.50, TLS: Connection closed, session=<64fELnha1u9o8/IE>
2026-09-02T06:08:08.768736+02:00 mail dovecot: auth-worker(3196538): conn unix:auth-worker (pid=1643206,uid=110): auth-worker<3260>: sql([email protected] ,104.243.242.4,<QFHYLnha2O9o8/IE>): unknown user
2026-09-02T06:08:15.238863+02:00 mail dovecot: auth-worker(3196538): conn unix:auth-worker (pid=1643206,uid=110): auth-worker<3261>: sql([email protected] ,104.243.242.4,<QFHYLnha2O9o8/IE>): unknown user
2026-09-02T06:08:21.557938+02:00 mail dovecot: auth-worker(3196538): conn unix:auth-worker (pid=1643206,uid=110): auth-worker<3263>: sql([email protected] ,104.243.242.4,<QFHYLnha2O9o8/IE>): unknown user
2026-09-02T06:08:23.435808+02:00 mail dovecot: imap-login: Disconnected: Connection closed (auth failed, 3 attempts in 15 secs): user=<gruppobrio@notels
...
show less
Brute-Force
Email Spam
Anonymous
2026-08-25 12:10:49
(3 weeks ago)
Credential Stuffing attacks against Microsoft 365
Brute-Force
๐บ๐ธ
threatintelligence_bvc
2026-08-20 07:41:11
(3 weeks ago)
Brute-Force