🇵🇱
Budyn
2026-09-08 21:21:04
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: kibana.goblinpot.tech | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇨🇦
SSH-Admin
2026-09-01 19:00:05
(1 week ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
🇨🇦
SSH-Admin
2026-09-01 18:05:02
(1 week ago)
Probing for Exploits on ns56
Exploited Host
Web App Attack
🇵🇱
Budyn
2026-09-01 09:47:09
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.sweetpuddingtrap.online | URI: /.git/HEAD | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-01 04:57:03
(1 week ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
🇦🇺
aranguren.org
2026-08-29 11:31:27
(1 week ago)
171.22.217.29 - - [29/Aug/2026:21:31:19 +1000] "GET /nagios/ HTTP/1.1" 401 1219 "-" "Mozilla/5.0 (Ma ...
show more
171.22.217.29 - - [29/Aug/2026:21:31:19 +1000] "GET /nagios/ HTTP/1.1" 401 1219 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
171.22.217.29 - - [29/Aug/2026:21:31:19 +1000] "GET /cgi-bin/dsc-grapher.pl HTTP/1.1" 401 1234 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
171.22.217.29 - - [29/Aug/2026:21:31:19 +1000] "GET /squid-reports HTTP/1.1" 401 1225 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
171.22.217.29 - - [29/Aug/2026:21:31:19 +1000] "GET /rutorrent/ HTTP/1.1" 401 1222 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
171.22.217.29 - - [29/Aug/2026:21:31:19 +1000] "GET /list.htm HTTP/1.1" 200 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML,
...
show less
Bad Web Bot
🇵🇱
Budyn
2026-08-27 12:33:54
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cache.dont-eat-the-pudding.top | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-24 06:25:10
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: status.dont-eat-the-pudding.xyz | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-16 09:15:25
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: backup.budyn.ovh | URI: /xmlrpc.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-12 03:22:27
(4 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: db.definitelynotahoneypot.online | URI: /xmlrpc.php | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
Lino Project
2026-08-01 04:28:10
(1 month ago)
171.22.217.29 - - [01/Aug/2026:06:28:09 +0200] "GET /xmlrpc.php HTTP/1.1" 403 595 "-" "Mozilla/5.0 ( ...
show more
171.22.217.29 - - [01/Aug/2026:06:28:09 +0200] "GET /xmlrpc.php HTTP/1.1" 403 595 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-07-25 04:32:57
(1 month ago)
Many_bad_calls
Web App Attack
🇧🇪
taivas.nl
2026-07-24 13:32:09
(1 month ago)
Bad_requests
Bad Web Bot
🇨🇭
backslash
2026-07-23 00:51:01
(1 month ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-17 01:49:59
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 171.22.217.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 171.22.217.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 21:49:53.805810 2026] [security2:error] [pid 10400:tid 10400] [client 171.22.217.29:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abdulhameeds.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abdulhameeds.art"] [uri "/ar/wp-json/wp/v2/users/1"] [unique_id "almKQQTfFsccazHc_kolrgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack