π΅π±
Budyn
2026-08-15 22:35:24
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: pma.budyn.ovh | URI: /phpmyadmin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π©πͺ
jbcrn
2026-08-15 14:42:15
(6 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
π©πͺ
Skyrider
2026-08-14 23:36:15
(1 week ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-14 08:11:26
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 04:11:20.818355 2026] [security2:error] [pid 14653:tid 14653] [client 2a03:2880:f800:1c:::26368] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellart.com"] [uri "/mitchellart.com"] [unique_id "an7NqB7NkQC2G2eLkYQLbQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Skyrider
2026-08-13 21:19:36
(1 week ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
πΊπΈ
Charlesiv
2026-08-13 20:01:29
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 32934 (Facebook, Inc.)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 32934 (Facebook, Inc.)
Protocol: HTTP/2 (GET method)
Endpoint: /
Query: ?lang=pt-pt
Timestamp: 2026-08-13T18:55:18Z
Ray ID: a2a9eeeaeced2036
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
show less
Bad Web Bot
π¬π§
relianoid.com
2026-08-13 17:47:31
(1 week ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-13 10:37:00
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 06:36:55.553628 2026] [security2:error] [pid 1101996:tid 1101996] [client 2a03:2880:f800:1c:::63900] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mininoarg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mininoarg.com"] [uri "/mininoarg.com"] [unique_id "an2eRzT8piQaTUxyhT641gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Skyrider
2026-08-12 20:24:34
(1 week ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 23:28:20
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 19:28:11.465545 2026] [security2:error] [pid 28786:tid 28786] [client 2a03:2880:f800:1c:::48686] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||roselockecasting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "roselockecasting.com"] [uri "/roselockecasting.com"] [unique_id "anuwC8tcIxaiN68j4nun6gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 01:43:07
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 21:43:01.383108 2026] [security2:error] [pid 1981167:tid 1981167] [client 2a03:2880:f800:1c:::33590] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||credenda.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "credenda.com"] [uri "/credenda.com"] [unique_id "anp-JYGvpdObs3xjvC5BTAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-10 06:43:16
(1 week ago)
[ns27.kdns.gr] httpd-noisy-crawler-swarm: sites=www.hristospanagia.gr; logs=/var/log/httpd/domains/h ...
show more
[ns27.kdns.gr] httpd-noisy-crawler-swarm: sites=www.hristospanagia.gr; logs=/var/log/httpd/domains/hristospanagia.gr.log; samples=crawler=meta-webindexer | window=5m | distinct_ips=34
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-09 17:24:09
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 13:24:04.125874 2026] [security2:error] [pid 3965407:tid 3965407] [client 2a03:2880:f800:1c:::38268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||natchezbicycle.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "natchezbicycle.com"] [uri "/natchezbicycle.com"] [unique_id "ani3tHFP1oAH5wES-waM1wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Skyrider
2026-08-09 16:45:07
(1 week ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
π©πͺ
Skyrider
2026-08-07 16:47:02
(2 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack