๐ฉ๐ช
LRob
2026-08-29 02:51:47
(11 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+5 more) | 2026-08-29 02:51 UTC
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-08-28 15:48:19
(22 hours ago)
213.163.199.231 - - [28/Aug/2026:17:48:19 +0200] "GET /public/plugins/bargauge/../../../../../../../ ...
show more
213.163.199.231 - - [28/Aug/2026:17:48:19 +0200] "GET /public/plugins/bargauge/../../../../../../../etc/passwd HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
213.163.199.231 - - [28/Aug/2026:17:48:19 +0200] "GET /api/fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/ HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
213.163.199.231 - - [28/Aug/2026:17:48:19 +0200] "GET /api/2.0/mlflow/artifacts/get?run_id=x&path=http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/ HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
213.163.199.231 - - [28/Aug/2026:17:48:19 +0200] "GET /public/plugins/table/../../../../../../../root/.aws/credentials HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
213.163.199.231 - - [28/Aug/2026:17:48:19 +0200] "GET /public/plugins/alertlist/../../../../../../../etc/passwd HTTP/1.1"
...
show less
DDoS Attack
Hacking
๐ต๐ฑ
Budyn
2026-08-28 09:12:40
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /api/v1/namespaces/default/secrets | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-08-28 06:57:24
(1 day ago)
28/Aug/2026:08:57:24.131705 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Aug/2026:08:57:24.131705 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 213.163.199.231] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /api/2.0/mlflow/artifacts/get?run_id=x&path=../../../../../../root/.aws/credentials"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "83.40.216.116"] [uri "/api/2.0/mlflow/a
...
show less
Hacking
Web App Attack
๐บ๐ธ
jormaster3k
2026-08-28 06:50:18
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฉ๐ช
Blexyel
2026-08-27 20:10:47
(1 day ago)
213.163.199.231 - - [27/Aug/2026:22:10:47 +0200] "GET /.git/config HTTP/1.1" 200 264 "-" "Mozilla/5. ...
show more
213.163.199.231 - - [27/Aug/2026:22:10:47 +0200] "GET /.git/config HTTP/1.1" 200 264 "-" "Mozilla/5.0" "136.243.2.38"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
Feelautom
2026-08-27 14:06:22
(1 day ago)
[FeelAutom Auto-Ban] DirectIpScan: /api/health (Score: 200)
Hacking
๐ฉ๐ช
cloudmax
2026-08-27 07:31:19
(2 days ago)
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnera ...
show more
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnerability probing
show less
Port Scan
๐ฉ๐ช
hero2026
2026-08-26 22:15:50
(2 days ago)
Blocked by Fail2ban
Web App Attack
๐บ๐ธ
ThreatHunter7
2026-08-26 18:00:05
(2 days ago)
Malicious scanning/attack activity detected. 64 suspicious requests from this IP.
Web App Attack