๐ต๐ฑ
Budyn
2026-08-16 07:19:14
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: test.budyn.ovh | URI: /wp-admin/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-15 20:27:05
(2 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 17:35:57
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 13:35:52.491534 2026] [security2:error] [pid 20243:tid 20243] [client 2a03:2880:f800:2d:::43102] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mininoarg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mininoarg.com"] [uri "/mininoarg.com"] [unique_id "aoCjeA203RMte9geET-HNwAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
alcacerlab
2026-08-15 08:35:33
(2 weeks ago)
2a03:2880:f800:2d:: - - [15/Aug/2026:05:35:31 -0300] "GET / HTTP/2" 200 54000 "-" "facebookexternalh ...
show more
2a03:2880:f800:2d:: - - [15/Aug/2026:05:35:31 -0300] "GET / HTTP/2" 200 54000 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-14 14:42:24
(2 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ฌ๐ง
relianoid.com
2026-08-13 16:25:45
(2 weeks ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
๐ต๐ฑ
Budyn
2026-08-12 20:41:58
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: s1.budyn.ovh | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-12 20:22:11
(2 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 03:45:02
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 23:44:57.140537 2026] [security2:error] [pid 344057:tid 344057] [client 2a03:2880:f800:2d:::37992] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||danged.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danged.com"] [uri "/danged.com"] [unique_id "anqauaHk4qH703QY9J6c4wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-09 14:24:18
(3 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 21:01:45
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 17:01:37.738643 2026] [security2:error] [pid 163613:tid 163613] [client 2a03:2880:f800:2d:::46356] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lumentravel.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lumentravel.com"] [uri "/lumentravel.com"] [unique_id "aneZMQiswjoxgX8KSLb-PwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-07 14:56:35
(3 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 04:35:34
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 00:35:27.132548 2026] [security2:error] [pid 613429:tid 613429] [client 2a03:2880:f800:2d:::30952] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "anQPD9cneEyLrp_kIh0JhgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-05 15:30:58
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 11:30:53.580489 2026] [security2:error] [pid 3019814:tid 3019814] [client 2a03:2880:f800:2d:::49236] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.adonamusic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.adonamusic.com"] [uri "/adonamusic.com"] [unique_id "anNXLYaO76ArI42AV9MG1wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-05 15:07:48
(3 weeks ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack