๐บ๐ธ
TPI-Abuse
2026-10-09 19:39:50
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:367:cff2:3391:70b:eda2:5379:b07b (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:367:cff2:3391:70b:eda2:5379:b07b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:39:46.514208 2026] [security2:error] [pid 5167:tid 5167] [client 2a01:367:cff2:3391:70b:eda2:5379:b07b:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.forsaleincr.com"] [uri "/.env"] [unique_id "aslDAmIhyn5-MpWBeD0H8QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-10-09 14:04:04
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-10-09 12:08:31
(18 hours ago)
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-09 10:39:59
(19 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
Marcel Bachmann
2026-10-09 00:24:36
(1 day ago)
Automated web scanner detected by HAProxy Security Center. Reason: Fail2ban HAProxy Scanner
Web App Attack
๐บ๐ธ
infra-monitor
2026-10-08 20:00:04
(1 day ago)
Automated ban via infra-monitor: suspicious-probe
Port Scan
๐ต๐ฑ
Budyn
2026-10-07 21:32:42
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: backup.sweetpuddingtrap.online | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-07 16:34:38
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.teddypot.cloud | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-07 13:27:12
(2 days ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a01:367:cff2:3391:70b:eda2:5379:b07b - - [07/Oct/2026:15:27:11 +0200] "GET /.env HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-07 04:09:03
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.sweetpuddingtrap.online | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-06 22:16:14
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: backup.definitelynotahoneypot.online | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-06 17:34:02
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: backup.astropot.site | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-06 13:06:31
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.astropot.site | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-10-06 11:38:34
(3 days ago)
forbidden http request, scanning for weaknesses
...
Web App Attack
๐ซ๐ฎ
KTSTechnology
2026-10-06 01:03:09
(4 days ago)
Web vulnerability scanning detected by our ISP firewall
Web App Attack