Anonymous
2026-05-21 17:04:08
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
Watto
2026-05-16 02:51:42
(4 weeks ago)
Honeypot caught web brute force / scanning from United States; 28 events recorded by kiosk-watchtowe ...
show more
Honeypot caught web brute force / scanning from United States; 28 events recorded by kiosk-watchtower (Cowrie + canary stack). Automated report from honeypot, please do not contact owner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-06 07:05:22
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-04 10:05:37
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-02 02:05:33
(2 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-01 01:06:32
(2 months ago)
Scanning/Probing (22)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-31 00:07:27
(2 months ago)
Scanning/Probing (27)
Brute-Force
Web App Attack
Anonymous
2026-03-27 20:18:33
(2 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 12:37:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 08:37:49.732697 2026] [security2:error] [pid 14525:tid 14525] [client 162.158.78.170:11789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jenricker.com"] [uri "/.env_config"] [unique_id "acZ6HY-6Vwgdoq4S8fG_owAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 10:33:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 06:33:21.781727 2026] [security2:error] [pid 15405:tid 15405] [client 162.158.78.170:12065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.plava.org"] [uri "/.env.bak"] [unique_id "acZc8UaVwYJARLUpiMkFygAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 02:40:45
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 22:40:39.083301 2026] [security2:error] [pid 24058:tid 24058] [client 162.158.78.170:13144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gwenwaltersartrep.com"] [uri "/.env~"] [unique_id "acXuJ_SVnE5xJNe5v4_ApgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-26 13:05:29
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 12:23:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 08:22:42.621624 2026] [security2:error] [pid 2712:tid 2712] [client 162.158.78.170:13889] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.digitalsolutions.help"] [uri "/.env.production"] [unique_id "acUlEl90EafKr-j54CgbrAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 03:54:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 23:53:40.115758 2026] [security2:error] [pid 25385:tid 25385] [client 162.158.78.170:11703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tomweston.net"] [uri "/docker/.env"] [unique_id "acStxNH5DK7IOcKy9Z1MuAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 02:15:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 22:15:13.106811 2026] [security2:error] [pid 29333:tid 29333] [client 162.158.78.170:9462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mikeziegler.com"] [uri "/.env.orig"] [unique_id "acSWsTdcDBpyvqtaKE3GfQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack