๐ต๐ฑ
Budyn
2026-09-02 16:25:48
(34 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: app.goblinpot.site | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-01 02:32:04
(1 day ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-30 23:03:25
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.teddypot.online | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-30 07:06:28
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: telemetry.sweetpuddingtrap.online | URI: /backup.sql | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 00:50:54
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:48:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:48:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:50:50.725012 2026] [security2:error] [pid 27899:tid 27899] [client 2a03:2880:f804:48:::62632] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.baselinesc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.baselinesc.com"] [uri "/baselinesc.com"] [unique_id "ao44atmme4taod23vRsmnAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 07:22:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:48:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:48:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 03:22:26.910120 2026] [security2:error] [pid 32757:tid 32757] [client 2a03:2880:f804:48:::56144] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kclawoffice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kclawoffice.com"] [uri "/kclawoffice.com"] [unique_id "aof8sgD59W32B15ub2OluwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-08-19 22:00:15
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐ง๐ท
alcacerlab
2026-08-14 23:42:11
(2 weeks ago)
2a03:2880:f804:48:: - - [14/Aug/2026:20:42:10 -0300] "GET / HTTP/2" 200 54000 "-" "facebookexternalh ...
show more
2a03:2880:f804:48:: - - [14/Aug/2026:20:42:10 -0300] "GET / HTTP/2" 200 54000 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-08-14 07:53:18
(2 weeks ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-08 00:45:16
(3 weeks ago)
CrowdSec: REPEAT OFFENDER (previously banned, came back) - distributed L7 HTTP flood on WordPress 'T ...
show more
CrowdSec: REPEAT OFFENDER (previously banned, came back) - distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/page_offset~-1/tag_ids~725,475,702,401,253,671/request_format~json/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/
show less
DDoS Attack
Web App Attack
๐บ๐ธ
ersei.net
2026-06-14 11:25:39
(2 months ago)
Brute force multiple 403s
Brute-Force
๐บ๐ธ
ersei.net
2026-06-10 02:05:19
(2 months ago)
Brute force multiple 403s
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-23 01:44:52
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:48:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:48:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 21:44:43.842819 2026] [security2:error] [pid 3462:tid 3462] [client 2a03:2880:f804:48:::47483] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoretopicturenetwork.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoretopicturenetwork.com"] [uri "/scoretopicturenetwork.com"] [unique_id "ahEGi-Y5OsM8IdrJMOKaUgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ersei.net
2026-03-21 08:56:17
(5 months ago)
Nonstop scanning with no cooldown or respect for 429.
Bad Web Bot
๐ณ๐ฑ
Roderic
2026-01-05 22:16:34
(7 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot