πΊπΈ
[email protected]
2026-10-08 22:52:50
(44 minutes ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 30h14m4s)
Web App Attack
π©πͺ
itsolon
2026-10-08 19:36:28
(4 hours ago)
[08/Oct/2026:21:36:28 +0200] 17914881881.646087 195.178.110.94 35234 217.154.7.177 443
[08/Oct/2026: ...
show more
[08/Oct/2026:21:36:28 +0200] 17914881881.646087 195.178.110.94 35234 217.154.7.177 443
[08/Oct/2026:21:36:28 +0200] 179148818822.353925 195.178.110.94 35196 217.154.7.177 443
[08/Oct/2026:21:36:28 +0200] 179148818863.027596 195.178.110.94 35214 217.154.7.177 443
[08/Oct/2026:21:36:28 +0200] 17914881880.489439 195.178.110.94 35194 217.154.7.177 443
[08/Oct/2026:21:36:28 +0200] 179148818829.981329 195.178.110.94 35266 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π΅π±
Budyn
2026-10-08 19:06:42
(4 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: prometheus.goblinpot.online | URI: /.zsh_history | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-10-08 18:41:42
(4 hours ago)
T: f2b 404 5x
Web App Attack
πΊπΈ
Penny Packer
2026-10-08 18:15:09
(5 hours ago)
Fail2Ban apache-404
Web App Attack
π«π·
seyess
2026-10-08 15:34:48
(8 hours ago)
Detected by CrowdSec on our edge (reported by Eyes Cyberteam - security monitoring (Inquire.sh)). Sc ...
show more
Detected by CrowdSec on our edge (reported by Eyes Cyberteam - security monitoring (Inquire.sh)). Scenarios: crowdsecurity/http-crawl-non_statics, crowdsecurity/http-probing, crowdsecurity/http-sensitive-files. Events: 7 between 2026-10-06 11:27 UTC and 2026-10-07 04:54 UTC. Targets observed: /.auth.json, /.bash_history, /.composer-auth.json, /.docker/config.json. Action taken locally: ban.
show less
Port Scan
Hacking
Bad Web Bot
π΅π±
Budyn
2026-10-08 15:05:55
(8 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jenkins.dont-eat-the-pudding.top | URI: /.auth.json | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-10-08 15:05:20
(8 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
π©πͺ
macrob
2026-10-08 11:33:24
(12 hours ago)
2026/10/08 11:33:23 [error] 1030188#1030188: *29863108 access forbidden by rule, client: 195.178.110 ...
show more
2026/10/08 11:33:23 [error] 1030188#1030188: *29863108 access forbidden by rule, client: 195.178.110.94, server: binixo.ro, request: "GET /.azure-pipelines.yml HTTP/2.0", host: "binixo.ro"
2026/10/08 11:33:23 [error] 1030193#1030193: *29825593 access forbidden by rule, client: 195.178.110.94, server: binixo.ro, request: "GET /.config/gcloud/access_tokens.db HTTP/2.0", host: "binixo.ro"
2026/10/08 11:33:23 [error] 1030189#1030189: *29864285 access forbidden by rule, client: 195.178.110.94, server: binixo.ro, request: "GET /.boto HTTP/2.0", host: "binixo.ro"
...
show less
Web App Attack
Anonymous
2026-10-08 10:48:39
(12 hours ago)
Automated web probe/scanner blocked at the edge (WorldTree fleet). Signature: probe_path. Example re ...
show more
Automated web probe/scanner blocked at the edge (WorldTree fleet). Signature: probe_path. Example request: /sites/default/settings.php.orig on apr.ai
show less
Web App Attack
Bad Web Bot
π΅π±
Budyn
2026-10-08 10:43:11
(12 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.astropot.online | URI: /.aws/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π¦πΊ
Martlark
2026-10-08 10:20:45
(13 hours ago)
Flask-IPban - exploit URL requested:/.config/sftp.json
Web App Attack
π«π·
arsonist
2026-10-08 08:59:52
(14 hours ago)
[fail2ban]
2026-10-08T08:59:51.324216+00:00 arson caddy[1712]: {"level":"info","ts":1791449991.32416 ...
show more
[fail2ban]
2026-10-08T08:59:51.324216+00:00 arson caddy[1712]: {"level":"info","ts":1791449991.3241618,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"195.178.110.94","remote_port":"19334","client_ip":"195.178.110.94","proto":"HTTP/2.0","method":"GET","host":"deluge.arson.gg","uri":"/.env","headers":{"Accept-Encoding":["gzip"],"Sec-Ch-Ua-Platform":["\"Linux\""],"Sec-Fetch-User":["?1"],"Sec-Ch-Ua":["\"Not.A/Brand\";v=\"8\", \"Chromium\";v=\"133\", \"Google Chrome\";v=\"133\""],"Sec-Fetch-Site":["none"],"Sec-Fetch-Dest":["document"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Ch-Ua-Mobile":["?0"],"Upgrade-Insecure-Requests":["1"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Fetch-Mode":["navig
...
show less
Bad Web Bot
π¨π¦
Sakusen
2026-10-08 08:54:26
(14 hours ago)
Automated web attack: 671 reqs, 282 paths probed, 577 returned 404; probed: 63 other, 47 .json, 45 . ...
show more
Automated web attack: 671 reqs, 282 paths probed, 577 returned 404; probed: 63 other, 47 .json, 45 .yml, 32 secret, 21 .php, 16 .env, 13 .sql, 12 config, 8 script, 7 .git, 7 .xml, 7 cloud-cred, 2 .jsp, 2 backup
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 08:10:54
(15 hours ago)
access denied too many times (more than 12 attempts in 60 seconds)
...
Web App Attack
Brute-Force