๐ต๐ฑ
Budyn
2026-09-16 13:49:28
(3 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.teddypot.pro | URI: /.well-known/security.txt | UA: CCBot/2.0 (https://commoncrawl.org/faq/) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-09-16 13:02:20
(4 hours ago)
154.58.229.28 - - [16/Sep/2026:15:02:19 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 124 "-" ...
show more
154.58.229.28 - - [16/Sep/2026:15:02:19 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 124 "-" "Mozilla/5.0 (compatible; xAI-SearchBot/1.0; +https://x.ai)"
154.58.229.28 - - [16/Sep/2026:15:02:19 +0200] "GET /.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
154.58.229.28 - - [16/Sep/2026:15:02:19 +0200] "GET /.env.local HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
154.58.229.28 - - [16/Sep/2026:15:02:19 +0200] "GET /.env.production HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
154.58.229.28 - - [16/Sep/2026:15:02:19 +0200] "GET /.env.development HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; xAI-SearchBot/1.0; +https://x.ai)"
154.58.229.28 - - [16/Sep/2026:15:02:19 +0200] "GET /.env.backup HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
154.58.229.
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 11:17:25
(6 hours ago)
[cb-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 154.58.229.28 - - [16/Sep/2026:13:17:03 +0200] "GET /.env.production HTTP/2.0" 403 87 "http://cherrypicking.nl/.env.production" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 10:52:07
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
debestelapp
2026-09-16 10:30:13
(6 hours ago)
Web App Attack
๐ต๐ฑ
Budyn
2026-09-16 09:47:16
(7 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: app.sweetpuddingtrap.online | URI: /.well-known/security.txt | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-16 08:07:52
(9 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-15 22:15:58
(19 hours ago)
Brute-Force
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-15 22:00:25
(19 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 154.58.229.28 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 154.58.229.28 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 21:59:04
(19 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: backup.teddypot.cloud | URI: /.env.local | UA: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-15 21:55:15
(19 hours ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
๐ณ๐ด
Bots.go.to.hell
2026-09-15 20:47:47
(20 hours ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
๐บ๐ธ
its101
2026-09-15 18:25:08
(22 hours ago)
Automated detection by LockdownAccess security system. Attack type(s): config_probe, env_grab, frame ...
show more
Automated detection by LockdownAccess security system. Attack type(s): config_probe, env_grab, framework_probe, git_exposure. Reason: Nginx: env_grab attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-15 17:44:53
(23 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-15 16:29:37
(1 day ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack