🇵🇱
Budyn
2026-09-03 15:22:55
(3 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.ovh | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 16:30:01
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 12:29:56.172957 2026] [security2:error] [pid 31549:tid 31549] [client 2001:41d0:701:1100::5eff:58030] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".ventolin.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/www.ventolin.com"] [unique_id "apWsBETLxWtML95NHSrj-gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-31 09:00:28
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: status.teddypot.store | URI: /backup.sql | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 07:58:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh. ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:58:18.336334 2026] [security2:error] [pid 13427:tid 13427] [client 2001:41d0:701:1100::5eff:41234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "genesis-castle.com"] [uri "/wp-config.php"] [unique_id "apU0GlmFHzO4YzKNDrgypAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-23 14:20:57
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.xyz | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇵🇱
Budyn
2026-08-23 08:28:08
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: pma.definitelynotahoneypot.top | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-23 00:59:28
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: ldap.teddypot.site | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-22 20:03:44
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: minio.goblinpot.space | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-08-22 03:53:37
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /fediverse/post/deflagration.hematocystis/delinquence/blastomycotic-inharmonical/. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-08-20 04:17:36
(2 weeks ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /fediverse/post/deflagration.oligometochic/anubing-aftergas/planetkin-productoid/. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-19 18:11:33
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 14:11:27.771206 2026] [security2:error] [pid 23974:tid 23974] [client 2001:41d0:701:1100::5eff:36298] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bahamascruisersguide.com|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bahamascruisersguide.com"] [uri "/page26/snowbirdscompassrose.blogspot.com"] [unique_id "aoXxzxjc97UrGYX3w4Qy8wAAAHU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-08-19 00:12:45
(2 weeks ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /fediverse/post/deflagration.oligometochic/nomogeny-cursorary/plical/heteradenic-unhard-insure.png. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 13:10:12
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 09:10:05.545794 2026] [security2:error] [pid 8763:tid 8763] [client 2001:41d0:701:1100::5eff:41702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||phantomkennels.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "phantomkennels.com"] [uri "/[email protected] "] [unique_id "aoRZrVHzJBcaFxKzS73xWQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 05:43:30
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 01:43:24.592866 2026] [security2:error] [pid 14168:tid 14171] [client 2001:41d0:701:1100::5eff:59540] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jean-paullederer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jean-paullederer.com"] [uri "/[email protected] "] [unique_id "aoPw_BSB-zO19vSdl7K8gQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 02:54:12
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:701:1100::5eff (vps-d57b59bf.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:54:04.698181 2026] [security2:error] [pid 10175:tid 10175] [client 2001:41d0:701:1100::5eff:38198] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.homebuilt.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.homebuilt.org"] [uri "/directory/[email protected] "] [unique_id "aoJ3zPbvdbRY53xO_lixrgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack