🇩🇪
conseilgouz
2026-08-25 21:23:43
(4 days ago)
vew-(visforms) : try to access forms...
Hacking
🇫🇷
abuseipdb.amaze321
2026-08-25 00:36:52
(5 days ago)
Automated reconnaissance: repeated requests for sensitive/non-existent paths.
Web App Attack
Bad Web Bot
🇵🇱
Budyn
2026-08-24 04:07:22
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: elastic.dont-eat-the-pudding.top | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-23 18:51:54
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cloud.teddypot.tech | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-23 01:31:31
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: nexus.definitelynotahoneypot.online | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-22 21:08:27
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: s3.sweetpuddingtrap.top | URI: /backup.sql | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
webgobe
2026-08-22 18:44:25
(1 week ago)
wew-Joomla User : try to access forms...
Hacking
🇩🇪
jbcrn
2026-08-22 16:10:53
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /fediverse/post/deflagration.thrombase/telotrochous-stinkingness/necromancing-bridgeman/precentrum-triseme-dialectics.png. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-08-20 21:26:31
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /fediverse/post/deflagration.oligometochic/kilp-incentive/festoonery/terebenic-clerkish.png. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 09:03:41
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:367:caf::1 (vps-1e2cbbf8.vps.ovh.net) ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:367:caf::1 (vps-1e2cbbf8.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 05:03:34.578943 2026] [security2:error] [pid 7740:tid 7753] [client 2001:41d0:367:caf::1:53268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dasperformance.com|F|2"] [data ".das performance.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dasperformance.com"] [uri "/the-harley-davidson-twin-cam/W WW.DAS performance.com"] [unique_id "aobC5k4Dc0ImzBkHybIxwQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 01:42:05
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:367:caf::1 (vps-1e2cbbf8.vps.ovh.net) ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:367:caf::1 (vps-1e2cbbf8.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 21:41:57.781429 2026] [security2:error] [pid 25307:tid 25307] [client 2001:41d0:367:caf::1:41246] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bahamascruisersguide.com|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bahamascruisersguide.com"] [uri "/Blogs-Websites/snowbirdscompassrose.blogspot.com"] [unique_id "aoZbZTlAFXisoNA8VifHiQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-08-18 12:06:27
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /fediverse/post/deflagration.oligometochic/reassortment/Butomaceae-Didunculidae/fluxibly-hydromel.png. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-08-17 06:28:14
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /fediverse/post/deflagration.oligometochic/Negroization/bara/flagroot-overland-ceratoglossal-Ostracoidea.png. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇦🇺
MAGIC
2026-08-17 05:00:51
(1 week ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇩🇪
filstal.org
2026-08-17 02:02:00
(1 week ago)
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. U ...
show more
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack