๐ซ๐ท
EvoX
2026-09-16 21:13:41
(21 hours ago)
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Incoming HTTP request (dst port 81/tcp, src port 35554) against a pa ...
show more
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Incoming HTTP request (dst port 81/tcp, src port 35554) against a passive decoy web service with no legitimate content. Consistent with automated web scanning/exploitation attempts.
show less
Hacking
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-09-15 18:50:29
(1 day ago)
cloudlinux2 fail2ban: 2026-09-15 20:45:21,629 fail2ban.filter [1908]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-15 20:45:21,629 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 101.26.28.147 - 2026-09-15 20:45:21cloudlinux2 fail2ban: 2026-09-15 20:46:08,053 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Unban 34.187.43.131cloudlinux2 fail2ban: 2026-09-15 20:47:34,280 fail2ban.filter [1908]: INFO [plesk-proftpd] Found 107.173.112.194 - 2026-09-15 20:47:34cloudlinux2 fail2ban: 2026-09-15 20:47:32,675 fail2ban.filter [1908]: INFO [plesk-proftpd] Found 193.140.29.5 - 2026-09-15 20:47:32cloudlinux2 fail2ban: 2026-09-15 20:47:48,010 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 34.16.114.1 - 2026-09-15 20:47:48cloudlinux2 fail2ban: 2026-09-15 20:47:47,990 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 34.16.114.1 - 2026-09-15 20:47:47cloudlinux2 fail2ban: 2026-09-15 20:47:48,146 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 34.16.114.1 - 2026-09-15 20:47:48cloudlinux2 fail2ban: 2026-09-
show less
FTP Brute-Force
๐ต๐ฑ
Budyn
2026-09-14 13:34:21
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.teddypot.tech | URI: /core/.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-09-13 04:45:40
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: portal.sweetpuddingtrap.xyz | URI: /.env.local | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-09-10 05:36:21
(1 week ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local | 2026-09-10 05:36 UTC
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-09-08 15:38:35
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: portal.sweetpuddingtrap.xyz | URI: /.env.example | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-08 07:54:58
(1 week ago)
Repeated 403 Forbidden responses
Web App Attack
๐ฉ๐ช
Reinhard
2026-09-07 10:37:36
(1 week ago)
Parameter or path manipulation, hacking. /app/config/parameters.yml
Hacking
๐ซ๐ท
EvoX
2026-09-01 09:29:00
(2 weeks ago)
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Incoming HTTP request (dst port 81/tcp, src port 47870) against a pa ...
show more
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Incoming HTTP request (dst port 81/tcp, src port 47870) against a passive decoy web service with no legitimate content. Consistent with automated web scanning/exploitation attempts.
show less
Hacking
Bad Web Bot
๐ฉ๐ช
MusicLibrary
2026-08-24 23:58:50
(3 weeks ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.fransveldman.world
2026-08-11 21:24:59
(1 month ago)
Fetched browser challenge page 10 times in <2h without solving. Likely bad bot.
Bad Web Bot
๐ฆ๐บ
electronico
2026-08-01 20:19:46
(1 month ago)
107.173.112.194 - - [02/Aug/2026:07:19:44 +1100] "GET /core/.env HTTP/1.1" 404 7466 "-" "Mozilla/5.0 ...
show more
107.173.112.194 - - [02/Aug/2026:07:19:44 +1100] "GET /core/.env HTTP/1.1" 404 7466 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36"
107.173.112.194 - - [02/Aug/2026:07:19:44 +1100] "GET /vendor/laravel/.env HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36"
107.173.112.194 - - [02/Aug/2026:07:19:44 +1100] "GET /storage/.env HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36"
107.173.112.194 - - [02/Aug/2026:07:19:44 +1100] "GET /protected/.env HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36"
107.173.112.194 - - [02/Aug/2026:07:19:44 +1100] "GET /newsite/.env HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) C
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 17:23:55
(1 month ago)
(mod_security) mod_security (id:210410) triggered by 107.173.112.194 (107-173-112-194-host.colocross ...
show more
(mod_security) mod_security (id:210410) triggered by 107.173.112.194 (107-173-112-194-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:23:51.702457 2026] [security2:error] [pid 3284670:tid 3284691] [client 107.173.112.194:47024] ModSecurity: Access denied with code 403 (phase 2). Found 3 byte(s) in ARGS:f outside range: 1-255. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "95"] [id "210410"] [rev "4"] [msg "COMODO WAF: Invalid character in request||uoexpanse.com|F|3"] [data "ARGS:f=14' \\x00AND 1=EXTRACTVALUE(1, CONCAT(0x7e21,(\\x00SELECT VERSION()),0x217e)) \\x00AND '1'='1"] [severity "ERROR"] [tag "CWAF"] [tag "Protocol"] [hostname "uoexpanse.com"] [uri "/forums/viewtopic.php"] [unique_id "amzaJ01PWtTZE9bivL-7ogAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.fransveldman.world
2026-07-31 16:54:10
(1 month ago)
Fetched browser challenge page 12 times in <2h without solving. Likely bad bot.
Bad Web Bot
๐ฉ๐ช
legrx
2026-07-31 16:34:58
(1 month ago)
Fetched browser challenge page 11 times in <2h without solving. Likely bad bot.
Bad Web Bot