π΅π±
Budyn
2026-10-11 04:56:01
(48 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: backup.dont-eat-the-pudding.top | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π¨π¦
zXero
2026-10-11 02:24:00
(3 hours ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
π©πͺ
Starburst SysOp Team
2026-10-11 01:15:53
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-nue6-2)
Hacking
Web App Attack
π¬π§
consul.to
2026-10-10 19:11:52
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-10-10 16:21:48
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
π΅π±
Budyn
2026-10-10 09:35:56
(20 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cloud.goblinpot.online | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-10-09 06:31:26
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jenkins.sweetpuddingtrap.xyz | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 04:21:59
(2 days ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2026-10-09 03:40:28
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 03:26:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 152.233.24.22 (unn-152-233-24-22.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 152.233.24.22 (unn-152-233-24-22.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:25:56.912584 2026] [security2:error] [pid 19211:tid 19211] [client 152.233.24.22:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jims-bbs.com"] [uri "/.env.txt"] [unique_id "ashexCe0HNfkKQ0-jkv5awAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-10-08 22:41:59
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: radius.astropot.store | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π©πͺ
Blexyel
2026-10-07 15:35:01
(3 days ago)
152.233.24.22 - - [07/Oct/2026:17:35:00 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
152.233.24.22 - - [07/Oct/2026:17:35:00 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
π³π΄
Bots.go.to.hell
2026-10-07 13:30:46
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-env-access
Web App Attack
Hacking
Anonymous
2026-10-07 11:49:17
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 22:23:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 152.233.24.22 (unn-152-233-24-22.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 152.233.24.22 (unn-152-233-24-22.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:23:18.893913 2026] [security2:error] [pid 27345:tid 27345] [client 152.233.24.22:50338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.accordionstars.com.accordionclub.org"] [uri "/.env.txt"] [unique_id "asV01sKr3kX_HAQGTN2sVgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack