π³π±
Savvii
2026-08-31 10:32:28
(1 day ago)
20 attempts against mh_ha-misbehave-ban on sedna
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
drewf.ink
2026-08-30 01:23:07
(2 days ago)
[01:23] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[01:23] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
π«π·
Sklurk
2026-08-02 02:17:23
(4 weeks ago)
Web App Attack
Web App Attack
π«π·
Sklurk
2026-08-01 00:30:01
(1 month ago)
Web App Attack
Web App Attack
π¬π§
PeravixGroup
2026-06-11 01:54:22
(2 months ago)
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity ...
show more
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2025-11-25 05:41:19
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:41:11.643372 2025] [security2:error] [pid 12358:tid 12358] [client 216.26.242.143:36517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "walkerbay-estonia.vangentholding.com"] [uri "/.svn/wc.db"] [unique_id "aSVBd9tXeYWs6hkPs4GMYwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 04:48:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:48:48.217430 2025] [security2:error] [pid 3591:tid 3591] [client 216.26.242.143:13413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.danialias.com"] [uri "/.svn/wc.db"] [unique_id "aSU1MNqFWnHzLHZFFIFBbAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-25 04:30:52
(9 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
πΊπΈ
TPI-Abuse
2025-11-25 03:42:17
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:42:11.702562 2025] [security2:error] [pid 3051:tid 3051] [client 216.26.242.143:37721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rosoctechnologies.com"] [uri "/.svn/wc.db"] [unique_id "aSUlk9omZcbGUPQXQBZw8gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 02:55:10
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:55:03.203537 2025] [security2:error] [pid 12910:tid 12910] [client 216.26.242.143:35305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.polydorou.eu"] [uri "/.svn/wc.db"] [unique_id "aSUahys1VgsvKZr2kT7V_QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 01:32:44
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.242.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:32:40.137259 2025] [security2:error] [pid 17599:tid 17599] [client 216.26.242.143:56157] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.peterhmichael.com"] [uri "/.env"] [unique_id "aSUHOA2gD2vwWN1Ob1SDwgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2025-11-25 00:07:06
(9 months ago)
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probing.
show less
Web App Attack