๐ต๐ฑ
Budyn
2026-09-24 23:36:26
(25 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: keycloak.astropot.online | URI: /backup.sql | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ท๐บ
Mga Admin
2026-09-24 23:26:10
(36 minutes ago)
16.216.88.44 - - [25/Sep/2026:06:26:10 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs132650 H ...
show more
16.216.88.44 - - [25/Sep/2026:06:26:10 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs132650 HTTP/1.1" 400 34 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-24 18:44:36
(5 hours ago)
Botnet flood DDOS activity
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-24 14:17:45
(9 hours ago)
AetherFox VoidGuard detected: [Thu Sep 24 14:17:44.315175 2026] [authz_core:error] [pid 3964198:tid ...
show more
AetherFox VoidGuard detected: [Thu Sep 24 14:17:44.315175 2026] [authz_core:error] [pid 3964198:tid 3964234] [client 16.216.88.44:16384] AH01630: client denied by server configuration: proxy:https://[MASKED]/viewforum.php
...
show less
Bad Web Bot
Web App Attack
๐ท๐บ
genokrad
2026-09-24 04:23:00
(19 hours ago)
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible ...
show more
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; R"
show less
Port Scan
Web App Attack
๐ฎ๐ฉ
hermawan
2026-09-24 01:38:26
(22 hours ago)
[Thu Sep 24 08:38:22.420762 2026] [security2:error] [pid 14778:tid 139820957419200] [client 16.216.8 ...
show more
[Thu Sep 24 08:38:22.420762 2026] [security2:error] [pid 14778:tid 139820957419200] [client 16.216.88.44:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:user-agent. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "274"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:user-agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 request_line = GET /index.php/prakiraan-bulanan/4233-prakiraan-curah-hujan-bulanan/prakiraan-curah-hujan-bulanan-di-propinsi-jawa-timur/prakiraan-bulanan-curah-hujan-di-propinsi-jawa-timur-tahun-2024/555561553-prakiraan-bulanan-curah-hujan-bulan-desember-tahun-2024-update-dari-analisis-bulan-oktober-tahun-20..."] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-bulanan/4233-prakiraan-cur
...
show less
Email Spam
Hacking
๐ต๐ฑ
Budyn
2026-09-23 13:53:05
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: k8s.astropot.website | URI: /backup.sql | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 04:38:22
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 16.216.88.44 (reflectionbot-88-44.reflection.ai ...
show more
(mod_security) mod_security (id:210730) triggered by 16.216.88.44 (reflectionbot-88-44.reflection.ai): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 00:38:19.260439 2026] [security2:error] [pid 1783495:tid 1783495] [client 16.216.88.44:16384] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".thehowardtheatre.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/news/0410-william-fitzsimmons-spring-tour-update/www.thehowardtheatre.com"] [unique_id "arNXu1jjVg7AAs6ka0o6kwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
genokrad
2026-09-22 23:54:58
(2 days ago)
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible ...
show more
Website scan TCP 80/443 "/robots.txt" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; R"
show less
Port Scan
Web App Attack
๐ท๐บ
Mga Admin
2026-09-22 23:46:42
(2 days ago)
16.216.88.44 - - [23/Sep/2026:06:46:41 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs2854613 ...
show more
16.216.88.44 - - [23/Sep/2026:06:46:41 +0700] "GET /analysis/theta/ws?p=5e-8&r2=0.9&rs-id=rs2854613 HTTP/1.1" 400 34 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-22 21:02:35
(2 days ago)
(PERMBLOCK) 16.216.88.44 (US/United States/-) has had more than 2 temp blocks in the last 604800 sec ...
show more
(PERMBLOCK) 16.216.88.44 (US/United States/-) has had more than 2 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
Anonymous
2026-09-22 19:21:00
(2 days ago)
Multiple Violations by Botnets
Port Scan
Web App Attack
๐ฉ๐ช
Reinhard
2026-09-22 08:23:01
(2 days ago)
Unknown activity, but too many attacks with too many users.
Hacking
๐ฉ๐ช
netclix.gr
2026-09-22 07:09:42
(2 days ago)
(bot_qv) Bot Scraping QuickView 16.216.88.44 (US/United States/-): 1 in the last 4600 secs; Ports: * ...
show more
(bot_qv) Bot Scraping QuickView 16.216.88.44 (US/United States/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 16.216.88.44 - - [22/Sep/2026:10:09:38 +0300] "GET /index.php?dispatch=products.quick_view&n_items=12968%2C12927%2C12899%2C12586%2C10909%2C10910%2C10911%2C10912%2C10913%2C10916%2C11374%2C11404%2C11664%2C11853%2C11867%2C11873%2C11916&prev_url=index.php%3Fsort_by%3Dtimestamp%26sort_order%3Ddesc%26dispatch%3Dcategories.view%26category_id%3D105&product_id=11374 HTTP/2.0" 302 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36"
show less
Port Scan
๐ต๐ฑ
Budyn
2026-09-22 06:08:25
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: ssh.sweetpuddingtrap.top | URI: /backup.sql | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Reflectionbot/1.0; +https://reflection.ai/bot) Chrome/151.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack