πΈπ¬
AP
2026-08-21 21:19:08
(13 hours ago)
[scanmy.band] Blocked by automated security check: high AbuseIPDB confidence score.
Brute-Force
Web App Attack
π΅π±
Budyn
2026-08-21 18:21:29
(16 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Web Spam (Form Abuse). Unsolicite ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Web Spam (Form Abuse). Unsolicited bulk message (Form Spam) captured. Evidence:
HOST: panel.teddypot.store | URI: /contact.php | UA: Mozilla/5.0 (Linux; Android 5.1.1; SAMSUNG SM-G920P Build/LMY47X) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/3.2 Chrome/38.0.2125.102 Mobile Safari/537.36 | BODY: name=yqjqysffut&company_website=onnjuytzyk&email=xsnjtoyj%40immenseignite.info&message=lvhfrmsqetmtrswzqnoefglrdrspxv
--- SPAM DATA ---
(From: [email protected] )
[CSS TRAP TRIGGERED: Filled hidden field: onnjuytzyk]
lvhfrmsqetmtrswzqnoefglrdrspxv
show less
Web Spam
Web App Attack
π΅π±
Budyn
2026-08-21 10:41:00
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Web Spam (Form Abuse). Unsolicite ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Web Spam (Form Abuse). Unsolicited bulk message (Form Spam) captured. Evidence:
HOST: s3.dont-eat-the-pudding.online | URI: /contact.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36 | BODY: name=ruhdtkweql&company_website=omxjykidor&email=kqffovqg%40immenseignite.info&message=fknvkqfkfqwhvmqfmyjozxjzwxveos
--- SPAM DATA ---
(From: [email protected] )
[CSS TRAP TRIGGERED: Filled hidden field: omxjykidor]
fknvkqfkfqwhvmqfmyjozxjzwxveos
show less
Web Spam
Web App Attack
π΅π±
Budyn
2026-08-19 00:27:34
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: beta.teddypot.online | URI: /wp-admin/ | UA: Mozilla/5.0 (PlayStation 4 2.57) AppleWebKit/537.73 (KHTML, like Gecko) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π¬π§
relianoid.com
2026-08-18 11:19:04
(3 days ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam
π¦πΊ
aranguren.org
2026-08-17 23:27:36
(4 days ago)
2602:fa5d::8b - - [18/Aug/2026:09:26:16 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Wind ...
show more
2602:fa5d::8b - - [18/Aug/2026:09:26:16 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0"
2602:fa5d::8b - - [18/Aug/2026:09:26:19 +1000] "GET /ossec/ HTTP/1.1" 404 989 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0"
2602:fa5d::8b - - [18/Aug/2026:09:26:27 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)"
2602:fa5d::8b - - [18/Aug/2026:09:26:31 +1000] "GET /ossec/ HTTP/1.1" 404 989 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)"
2602:fa5d::8b - - [18/Aug/2026:09:27:05 +1000] "GET /nagios/ HTTP/1.1" 401 1223 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0"
2602:fa5d::8b - - [18/Aug/2026:09:27:35
...
show less
Bad Web Bot
π³π±
Site.eu
2026-08-17 05:23:36
(5 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-08-15 04:31:18
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::8b (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::8b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 00:31:02.613294 2026] [security2:error] [pid 10648:tid 10648] [client 2602:fa5d::8b:53820] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tecnoconce.cl|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tecnoconce.cl"] [uri "/p-php.ini"] [unique_id "an_rhpzRAC3wy6DC8_WYOAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-14 01:07:52
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: login.astropot.store | URI: /wp-admin/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.74.9 (KHTML, like Gecko) Version/7.0.2 Safari/537.74.9 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π«π·
Nicolmn
2026-08-13 22:38:01
(1 week ago)
Web form spam ( id mmwlz.l )
Web Spam
π΅π±
Budyn
2026-08-13 08:28:46
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: metrics.teddypot.store | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π΅π±
mscode.pl
2026-08-13 00:54:23
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from TR.
Action taken: BLOCK
ASN: 44382 (Fiba Cloud Operat ...
show more
Triggered Cloudflare WAF (firewallCustom) from TR.
Action taken: BLOCK
ASN: 44382 (Fiba Cloud Operation Company, LLC)
Protocol: HTTP/1.1 (GET method)
Zone: backup1.mscode.pl
Endpoint: /
UA: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.124 Safari/537.36
show less
Bad Web Bot
π©π°
donkzquixote
2026-08-11 12:32:30
(1 week ago)
Form submission spam detected
Web Spam
πΊπΈ
TPI-Abuse
2026-08-10 21:12:09
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::8b (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::8b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 17:11:54.919257 2026] [security2:error] [pid 51226:tid 51226] [client 2602:fa5d::8b:35642] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||timberwolf-construction.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "timberwolf-construction.com"] [uri "/mail to: [email protected] "] [unique_id "ano-mpAeK-SD0Z07WJc2_wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-10 19:41:56
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::8b (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::8b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 15:41:38.686897 2026] [security2:error] [pid 1342324:tid 1342324] [client 2602:fa5d::8b:44394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thevillageartcenter.pamelaweisberg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thevillageartcenter.pamelaweisberg.com"] [uri "/mailto:[email protected] "] [unique_id "anopcjvTDhghmuWGinC7NwAAABQ"], referer: https://www.thevillageartcenter.pamelaweisberg.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack