๐บ๐ธ
jormaster3k
2026-09-29 17:39:35
(1 week ago)
Attack against Apache (too many 404s)
Web App Attack
๐ต๐ฑ
Budyn
2026-09-29 06:07:18
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.definitelynotahoneypot.top | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 04:13:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 00:13:01.341330 2026] [security2:error] [pid 10812:tid 10812] [client 207.175.176.31:60702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.davidsonmanagement.net"] [uri "/.git/config"] [unique_id "ars6zX-D2U5PjLlp3_T1qwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-29 00:09:16
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 207.175.176.31 (BE/Belgium/31.176.175 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 207.175.176.31 (BE/Belgium/31.176.175.207.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-28 07:07:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 03:06:55.766580 2026] [security2:error] [pid 23777:tid 23777] [client 207.175.176.31:46996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digi-estudio.com"] [uri "/.git/config"] [unique_id "aroSD58bWild3MOnQBeRxgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 05:34:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:34:49.917733 2026] [security2:error] [pid 29789:tid 29789] [client 207.175.176.31:57702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cloudex.link"] [uri "/.git/config"] [unique_id "arn8eRHtv4uXfsG3QbSvGQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 02:29:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 22:29:35.723986 2026] [security2:error] [pid 23689:tid 23689] [client 207.175.176.31:38320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.therealseska.com"] [uri "/.git/config"] [unique_id "arXcjznE6K94OIpQaNwy0AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
NotACaptcha
2026-09-24 17:41:00
(2 weeks ago)
webserver:443 [24/Sep/2026] "POST / HTTP/1.1" 302 482 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 1 ...
show more
webserver:443 [24/Sep/2026] "POST / HTTP/1.1" 302 482 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
webserver:443 [24/Sep/2026] "GET /.git/config HTTP/1.1" 302 504 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
webserver:443 [24/Sep/2026] "POST / HTTP/1.1" 302 482 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
webserver:443 [24/Sep/2026] "POST / HTTP/1.1" 302 482 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
webserver:443 [24/Sep/2026] "POST / HTTP/1.1" 302 482 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
webserver:443 [24/Sep/2026] "GET / HTTP/1.1" 302 5897 "-" "Mozilla/5.0 (Macintosh; Intel Mac O...
show less
Web App Attack
๐จ๐ญ
flaus
2026-09-24 17:38:38
(2 weeks ago)
$f2bV_matches
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-23 21:51:50
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 00:34:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:34:01.948589 2026] [security2:error] [pid 5698:tid 5698] [client 207.175.176.31:47922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.timelord2067.com"] [uri "/.git/config"] [unique_id "arHM-Y6hSRLQjriNZZ_n1AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:49:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.31 (31.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:49:28.644715 2026] [security2:error] [pid 6906:tid 6906] [client 207.175.176.31:57956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lexie.org"] [uri "/.git/config"] [unique_id "arFgGCuarPKOZvDI8jNucAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 14:10:03
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-09-20 15:27:56
(2 weeks ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฎ๐น
VHosting
2026-08-04 09:20:03
(2 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack