๐ต๐ฑ
Budyn
2026-10-04 17:11:10
(56 minutes ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_6 | Action: AWS API Call | Token: d27d ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_6 | Action: AWS API Call | Token: d27dkqjofz7pprlk36nnrvhej | Client Tool: aws-sdk-go-v2/1.45.1 ua/2.1 os/linux lang/go#1.25.14 md/GOOS#linux md/GOARCH#amd64 api/ses#1.38.0 m/e
show less
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-04 13:55:48
(4 hours ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_4 | Action: AWS API Call | Token: 3a2 ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_4 | Action: AWS API Call | Token: 3a228y9iwzbmqpgsnaaic99y3 | Client Tool: aws-sdk-go-v2/1.45.1 ua/2.1 os/linux lang/go#1.25.14 md/GOOS#linux md/GOARCH#amd64 api/ses#1.38.0 m/e
show less
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-04 06:22:56
(11 hours ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_7 | Action: AWS API Call | Token: 4dv ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_7 | Action: AWS API Call | Token: 4dvmm7wgh55qaj86jjj1vqe1z | Client Tool: aws-sdk-go-v2/1.45.1 ua/2.1 os/linux lang/go#1.25.14 md/GOOS#linux md/GOARCH#amd64 api/ses#1.38.0 m/e
show less
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-03 20:48:05
(21 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: elastic.teddypot.pro | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-10-03 11:43:10
(1 day ago)
130.211.61.233 - - [03/Oct/2026:13:43:06 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Windows NT ...
show more
130.211.61.233 - - [03/Oct/2026:13:43:06 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "api.staging.melroy.org" 0.000
130.211.61.233 - - [03/Oct/2026:13:43:06 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "app.api.melroy.org" 0.000
130.211.61.233 - - [03/Oct/2026:13:42:45 +0200] "GET /webpack.json HTTP/1.1" 404 207 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "cijfers.melroy.org" 0.000
130.211.61.233 - - [03/Oct/2026:13:42:45 +0200] "GET /%22script/effects.js%22 HTTP/1.1" 404 207 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "cijfers.melroy.org" 0.000
130.211.61.233 - - [03/Oct/2026:13:42:45 +0200] "GET /%22script/javascript.js%22 HTTP/1.
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 10:00:33
(1 day ago)
(mod_security) mod_security (id:248270) triggered by 130.211.61.233 (233.61.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:248270) triggered by 130.211.61.233 (233.61.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 06:00:28.646483 2026] [security2:error] [pid 15440:tid 15440] [client 130.211.61.233:32712] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\$\\\\{jndi:(ldaps?|rmi|dns|iiop|nis|nds|corba|\\\\$\\\\{(?:lower|upper)):" at REQUEST_HEADERS:Referer. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "7626"] [id "248270"] [rev "1"] [msg "COMODO WAF: Remote code execution in Apache log4j||caitypopxart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "caitypopxart.com"] [uri "/"] [unique_id "asDSPP0vo8i1F8fs0wEqTQAAAGs"], referer: ${jndi:ldap://127.0.0.1/bifrost-probe}
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-10-03 04:33:14
(1 day ago)
Many_bad_calls
Web App Attack
๐ง๐ช
taivas.nl
2026-10-03 02:32:10
(1 day ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
OceanTreasure
2026-10-03 00:33:18
(1 day ago)
tcp/443; Git smart-HTTP repository clone attempt against an exposed .git directory (/.git/info/refs? ...
show more
tcp/443; Git smart-HTTP repository clone attempt against an exposed .git directory (/.git/info/refs?service=git-upload-pack): "GET /.git/info/refs" @ 2026-10-03T00:33:18Z [proxy]
show less
Web App Attack
๐ซ๐ท
Octopuce
2026-10-02 12:47:39
(2 days ago)
Aggressive web search of vulnerable pages: /.env.local /.env /config/database.yml /userdata/.env /ap ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /config/database.yml /userdata/.env /api/.env ...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 15:54:58
(4 days ago)
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 130.211.61.233 - - [30/Sep/2026:17:54:52 +0200] "GET /.env HTTP/1.1" 404 1434 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:52:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 130.211.61.233 (233.61.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.61.233 (233.61.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:52:33.906343 2026] [security2:error] [pid 14548:tid 14548] [client 130.211.61.233:20126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alianzafreight.com"] [uri "/.git/HEAD"] [unique_id "arz4AUSWL-WkuGH-K8S8_QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-09-30 08:41:59
(4 days ago)
common Web Exploits being scanned
Web App Attack
๐ต๐ฑ
Budyn
2026-09-30 07:43:39
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.astropot.tech | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-30 05:08:01
(4 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01]
Hacking
SQL Injection
Web App Attack