๐ต๐ฑ
Budyn
2026-09-22 10:58:18
(28 seconds ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.dont-eat-the-pudding.top | URI: /backup.sql | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2026-09-22 08:57:54
(2 hours ago)
[Tue Sep 22 15:57:49.571825 2026] [security2:error] [pid 23954:tid 140170678494912] [client 16.216.8 ...
show more
[Tue Sep 22 15:57:49.571825 2026] [security2:error] [pid 23954:tid 140170678494912] [client 16.216.88.236:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:user-agent. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "274"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 request_line = GET /index.php/profil/meteorologi/list-all-categories/4121-klimatologi/infografis/infografis-klimatologi/infografis-dasarian/infografis-dasarian-tahun-2022/555559293-infografis-dasarian-informasi-iklim-jatim-update-20-februari-tahun-2022 HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/4121-klimatologi/infografis/infografis-klimatol
...
show less
Email Spam
Hacking
Anonymous
2026-09-22 07:57:07
(3 hours ago)
Automated report (2026-09-22T03:57:07-04:00). Scraper detected.
Bad Web Bot
Anonymous
2026-09-22 06:51:40
(4 hours ago)
Automated report (2026-09-22T02:51:40-04:00). Scraper detected.
Bad Web Bot
๐ท๐บ
genokrad
2026-09-21 23:19:11
(11 hours ago)
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible ...
show more
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; R"
show less
Port Scan
Web App Attack
๐ท๐บ
Mga Admin
2026-09-21 22:30:17
(12 hours ago)
16.216.88.236 - - [22/Sep/2026:05:30:15 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs1116464 ...
show more
16.216.88.236 - - [22/Sep/2026:05:30:15 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs11164648 HTTP/1.1" 400 34 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
webgobe
2026-09-21 17:24:19
(17 hours ago)
wew-Joomla User : try to access forms...
Hacking
๐ฆ๐น
services.org.pl
2026-09-21 12:31:14
(22 hours ago)
connect() failed (111: Connection refused) while connecting to upstream, client: 16.216.88.236, serv ...
show more
connect() failed (111: Connection refused) while connecting to upstream, client: 16.216.88.236, server: keycloak.services.org.pl, request: "GET /robots.txt HTTP/1.1", upstream: "https://127.0.0.1:8443/robots.txt", host: "keycloak.services.org.pl"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 09:30:08
(1 day ago)
FortiWeb WAF: 99 attacks detected. Threat Score: 10000. Types: Block IP List(50), Client Management( ...
show more
FortiWeb WAF: 99 attacks detected. Threat Score: 10000. Types: Block IP List(50), Client Management(49). Origin: United States.
show less
Web App Attack
Anonymous
2026-09-21 06:21:26
(1 day ago)
Web attack
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:05:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 16.216.88.236 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 16.216.88.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:05:09.293982 2026] [security2:error] [pid 5379:tid 5379] [client 16.216.88.236:53249] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hayrun.com|F|2"] [data ".hayrun.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hayrun.com"] [uri "/blog/img_0690/www.hayrun.com"] [unique_id "arCQ1VO29ODiahnu5SN7DgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2026-09-21 02:02:08
(1 day ago)
[Mon Sep 21 09:02:07.829789 2026] [security2:error] [pid 58229:tid 139823574664896] [client 16.216.8 ...
show more
[Mon Sep 21 09:02:07.829789 2026] [security2:error] [pid 58229:tid 139823574664896] [client 16.216.88.236:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:user-agent. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "273"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 request_line = GET /index.php/profil/meteorologi/list-all-categories/4350-klimatologi/infografis/infografis-klimatologi/infografis-bulanan/infografis-bulanan-buletin/infografis-bulanan-buletin-tahun-2026/555562769-infografis-bulanan-prediksi-hujan-bulan-maret-april-mei-tahun-2026-update-dari-analisis-bulan-j..."] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categor
...
show less
Email Spam
Hacking
๐ฉ๐ช
Viveronese
2026-09-21 01:32:27
(1 day ago)
HTTP vulnerability scanning
Web App Attack
๐ซ๐ท
Sorgin Informatique
2026-09-20 23:08:50
(1 day ago)
soe-88 : Bloc AI bots=>/robots.txt(.ai)
Hacking
๐ท๐บ
genokrad
2026-09-20 21:59:42
(1 day ago)
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible ...
show more
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; R"
show less
Port Scan
Web App Attack