๐ต๐ฑ
Budyn
2026-09-09 19:59:39
(1 hour ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: shop.goblinpot.online | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-09 08:58:12
(12 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cdn.budyn.top | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 00:05:52
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:16:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:16:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:05:44.529894 2026] [security2:error] [pid 14579:tid 14579] [client 2a03:2880:f800:16:::30168] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||walkerweb.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "walkerweb.com"] [uri "/walkerweb.com"] [unique_id "aqCi2OAlY1YTvnOZwtE9xQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-08 09:55:57
(1 day ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-07 08:23:03
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: metrics.definitelynotahoneypot.online | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 01:20:59
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:16:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:16:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:20:53.208520 2026] [security2:error] [pid 8975:tid 8975] [client 2a03:2880:f800:16:::45464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.player-care.us|F|2"] [data ".spencerserolls.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.player-care.us"] [uri "/cb/www.spencerserolls.com"] [unique_id "ap4Rdb2gWQfgBw32dKHKogAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-04 11:07:13
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: pma.sweetpuddingtrap.top | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-04 09:54:55
(5 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 06:39:11
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:16:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:16:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:39:07.740837 2026] [security2:error] [pid 8819:tid 8819] [client 2a03:2880:f800:16:::25510] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sammour.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sammour.com"] [uri "/sammour.com"] [unique_id "appni0DjVlWOXwF8nrxX8AAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:59:04
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f800:16:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f800:16:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:58:55.883887 2026] [security2:error] [pid 2675:tid 2675] [client 2a03:2880:f800:16:::54188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iotgardening.nextngnr.com"] [uri "/Hmklo4.htaccess"] [unique_id "apnfj16sruTTDIhQmrr0CAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-03 20:26:10
(6 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-03 08:00:30
(6 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /booru | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Skyrider
2026-09-02 15:00:10
(1 week ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-02 11:54:30
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
abuseipdb.amaze321
2026-09-01 03:35:34
(1 week ago)
Automated reconnaissance: repeated requests for sensitive/non-existent paths.
Web App Attack
Bad Web Bot