Anonymous
2026-10-08 06:05:07
(3 minutes ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-08 06:01:17
(6 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from RO.
Action taken: BLOCK
ASN: 47890 (UNMANAGED LTD)
Pr ...
show more
Triggered Cloudflare WAF (firewallCustom) from RO.
Action taken: BLOCK
ASN: 47890 (UNMANAGED LTD)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.svn/wc.db
Timestamp: 2026-10-08T02:57:31Z
Ray ID: a471e0e8cfb9f406
UA: Mozilla/4.0 (PSP (PlayStation Portable); 2.00)
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2026-10-08 05:25:37
(42 minutes ago)
08/Oct/2026:07:25:36.477746 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
08/Oct/2026:07:25:36.477746 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 193.32.162.175] ModSecurity: Warning. Matched phrase "/.svn/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.svn/ found within REQUEST_FILENAME: /.svn/wc.db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "parrot.elhacker.net"] [uri "/.svn/wc.db"] [unique_id "ascpUKeeNjBo0NAqU9FDyAAABfU"]
...
show less
Hacking
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-08 05:16:05
(52 minutes ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ฉ๐ช
Tsumugi Kotobuki
2026-10-08 05:13:26
(54 minutes ago)
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 55 | Len: 60B | Win: ...
show more
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 55 | Len: 60B | Win: 32120(1) | F2B/ufw-honeypot@2026-10-08T05:13:26Z
show less
Port Scan
Hacking
๐ต๐ฑ
Budyn
2026-10-08 04:40:22
(1 hour ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.definitelynotahoneypot.top | URI: /.svn/wc.db | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
srebrakowski.com
2026-10-08 04:34:05
(1 hour ago)
crowdsec/waf-detected-exploits
Brute-Force
๐ฉ๐ช
jbcrn
2026-10-08 04:33:25
(1 hour ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /.svn/wc.db. User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Edg/101.0.1210.39
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:12:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 193.32.162.175 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 193.32.162.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:12:28.378241 2026] [security2:error] [pid 12705:tid 12732] [client 193.32.162.175:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthtravel.net"] [uri "/.svn/wc.db"] [unique_id "ascYLK6gQf43GEi0orVBzgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tsZero
2026-10-08 04:05:51
(2 hours ago)
Scan example: path=/.svn/wc.db status=302
Hacking
๐บ๐ธ
mawan
2026-10-08 03:29:29
(2 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-10-08 03:27:52
(2 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-08 02:58:51
(3 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
Takesh
2026-10-08 02:37:22
(3 hours ago)
Numbase auto-report: abuseipdb_known_bad_score_100
Bad Web Bot
๐ฉ๐ช
eposs-it.de
2026-10-08 02:35:15
(3 hours ago)
Blocked by os-abuseipdb; 9 hits, proto=tcp, ports=443,80
Port Scan
Hacking