🇩🇪
bluematrix
2026-09-03 08:01:25
(1 day ago)
crowdsecurity/http-sensitive-files - Ip 104.28.193.31 performed 'crowdsecurity/http-sensitive-files' ...
show more
crowdsecurity/http-sensitive-files - Ip 104.28.193.31 performed 'crowdsecurity/http-sensitive-files' (6 events over 6.170296061s) at 2026-09-03 08:01:30.875819888 +0000 UTC
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-08-30 10:47:57
(5 days ago)
20 attempts against mh-misbehave-ban on acorn
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-26 17:23:44
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-26 04:17:04
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: gitlab.dont-eat-the-pudding.online | URI: /.env.test | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-25 18:12:49
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: docker.definitelynotahoneypot.online | URI: /.env.save | UA: Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-25 07:57:35
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cdn.teddypot.online | URI: /.env.test | UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-25 00:46:33
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: auth.dont-eat-the-pudding.online | URI: /.env.development | UA: Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 08:54:09
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 104.28.193.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.28.193.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 04:54:03.707512 2026] [security2:error] [pid 14097:tid 14097] [client 104.28.193.31:27264] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||acme-aviation.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "acme-aviation.com"] [uri "/.env.bak"] [unique_id "aoQdq-e8TS85_WDq9XxjYwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 18:43:50
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.28.193.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.193.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 14:43:43.939204 2026] [security2:error] [pid 4907:tid 4907] [client 104.28.193.31:55180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acadianahero.com"] [uri "/.env.bak"] [unique_id "aoNWX8R0iQEaYCDUFfUt6QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-08-17 15:25:13
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /.env.orig | Evidence: abreupro.com 104.28.193.31 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.orig | Evidence: abreupro.com 104.28.193.31 - - [17/Aug/2026:17:23:17 +0200] \"GET /.env.orig HTTP/1.1\" 404 31273 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)\" GEOIP_COUNTRY_CODE=US | ASN: CLOUDFLARENET | Country: US
show less
Port Scan
Web App Attack
🇺🇸
ipblock.com
2026-08-04 13:28:00
(1 month ago)
IPBlock protected site ID [1887-mw].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 03:31:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.28.193.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.193.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 23:30:57.483682 2026] [security2:error] [pid 23611:tid 23611] [client 104.28.193.31:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.globetechsecurities.com"] [uri "/.env.example"] [unique_id "anFc8W5mkKVa506mfpitdAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack