🇵🇱
Budyn
2026-09-01 08:40:36
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /cgi-bin/masterCGI?ping=nomip&user=;id; | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-01 03:50:43
(1 day ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_11 | Action: AWS API Call | Token: 7lg ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_11 | Action: AWS API Call | Token: 7lggvodiip8vznhits5cv0986 | Client Tool: aws-cli/2.23.6 md/awscrt#1.0.0.dev0 ua/2.0 os/linux#6.12.73+deb13-cloud-amd64 md/arch#x86_64 lang/python#3.13.5 md/pyimpl#CPython cfg/retry-mode#standard md/...
show less
Hacking
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-30 12:11:36
(3 days ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9b ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9br2dhw9iulptrg3dmcbkxl | Client Tool: [aws-cli/2.23.6 md/awscrt#1.0.0.dev0 ua/2.0 os/linux#6.12.73+deb13-cloud-amd64 md/arch#x86_64 lang/python#3.13.5 md/pyimpl#CPython cfg/retry-mode#standard md...
show less
Hacking
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-30 05:34:42
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /.env | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇺🇸
drewf.ink
2026-08-30 04:44:02
(3 days ago)
[04:44] Probed unrecognized Docker API path '/api/v4/projects'
Hacking
🇺🇸
Execoop
2026-08-30 03:29:40
(3 days ago)
API LLM Recon (Ollama) (observed): 97 HTTP, 1.8m; attempted outbound scan; Ollama: /api/version,/v1/ ...
show more
API LLM Recon (Ollama) (observed): 97 HTTP, 1.8m; attempted outbound scan; Ollama: /api/version,/v1/models
show less
Hacking
Web App Attack
🇺🇸
drewf.ink
2026-08-30 03:12:37
(3 days ago)
[03:12] Probed unrecognized Docker API path '/.git/HEAD'
Hacking
🇺🇸
drewf.ink
2026-08-30 02:24:19
(3 days ago)
[02:24] Probed unrecognized Docker API path '/'
Hacking
🇵🇱
Budyn
2026-08-29 04:04:45
(4 days ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_6 | Action: AWS API Call | Token: d27d ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_6 | Action: AWS API Call | Token: d27dkqjofz7pprlk36nnrvhej | Client Tool: Python-urllib/3.13
show less
Hacking
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-08-28 09:18:55
(5 days ago)
08/28/2026-11:18:55.465470 107.189.29.61 Protocol: 6 ET SCAN Suspicious inbound to PostgreSQL port 5 ...
show more
08/28/2026-11:18:55.465470 107.189.29.61 Protocol: 6 ET SCAN Suspicious inbound to PostgreSQL port 5432
show less
Hacking
🇵🇱
Budyn
2026-08-28 01:00:34
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /cli?remoting=false&@/root/.aws/credentials | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇪🇸
el-brujo
2026-08-27 23:51:01
(5 days ago)
107.189.29.61 - - [28/Aug/2026:01:51:01 +0200] "GET /public/plugins/alertlist/../../../../../../../p ...
show more
107.189.29.61 - - [28/Aug/2026:01:51:01 +0200] "GET /public/plugins/alertlist/../../../../../../../proc/self/environ HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
107.189.29.61 - - [28/Aug/2026:01:51:01 +0200] "Connection: close" 400 226 "-" "-"
107.189.29.61 - - [28/Aug/2026:01:51:01 +0200] "GET /public/plugins/graph/../../../../../../../root/.aws/credentials HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
107.189.29.61 - - [28/Aug/2026:01:51:01 +0200] "GET /public/plugins/heatmap/../../../../../../../root/.aws/credentials HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
107.189.29.61 - - [28/Aug/2026:01:51:01 +0200] "GET /public/plugins/table/../../../../../../../proc/self/environ HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
107.189.29.61 - - [28/Aug/2026:01:51:01 +0200] "GET /public/plugins/table/../../../../../../../var/lib/grafana/grafana.db HTTP/1.1" 400 226 "-" "Mozill
...
show less
DDoS Attack
Hacking
🇵🇱
Budyn
2026-08-27 20:52:15
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /api/v1/namespaces/default/secrets | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-08-27 20:02:24
(6 days ago)
107.189.29.61 - - [27/Aug/2026:22:02:24 +0200] "GET /public/plugins/graph/../../../../../../../var/l ...
show more
107.189.29.61 - - [27/Aug/2026:22:02:24 +0200] "GET /public/plugins/graph/../../../../../../../var/lib/grafana/grafana.db HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
107.189.29.61 - - [27/Aug/2026:22:02:24 +0200] "GET /api/2.0/mlflow/artifacts/get?run_id=x&path=http://169.254.169.254/latest/meta-data/iam/security-credentials/role HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
107.189.29.61 - - [27/Aug/2026:22:02:24 +0200] "GET /public/plugins/heatmap/../../../../../../../etc/passwd HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
107.189.29.61 - - [27/Aug/2026:22:02:24 +0200] "GET /fetch?url=http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/ HTTP/1.1" 403 199 "-" "Mozilla/5.0"
107.189.29.61 - - [27/Aug/2026:22:02:24 +0200] "Connection: close" 400 226 "-" "-"
107.189.29.61 - - [27/Aug/2026:22:02:24 +0200] "GET /public/plugins/text/../../..
...
show less
DDoS Attack
Hacking
🇫🇷
Feelautom
2026-08-27 19:25:39
(6 days ago)
[FeelAutom Auto-Ban] DirectIpScan: /etc/passwd (Score: 350)
Hacking