π΅π±
Budyn
2026-09-02 23:33:45
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: mail.definitelynotahoneypot.online | URI: /wp-admin/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π«π·
abuseipdb.amaze321
2026-08-31 03:37:28
(2 days ago)
Automated reconnaissance: repeated requests for sensitive/non-existent paths.
Web App Attack
Bad Web Bot
πΈπ¬
securejdprop
2026-08-29 18:26:15
(4 days ago)
This IP was detected by CrowdSec triggering jendela/too-many-probing.
Hacking
Web App Attack
Brute-Force
π©πͺ
Skyrider
2026-08-28 10:36:02
(5 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-28 09:28:30
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: kibana.astropot.space | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-28 01:27:47
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: telemetry.teddypot.site | URI: /wp-admin/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π©πͺ
Skyrider
2026-08-27 08:32:12
(6 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 08:18:05
(1 week ago)
[26/Aug/2026:10:52:00 +0300] 178773072086.891735 2a03:2880:f814:36:: 57188 2a01:4f8:202:41d3::2 443
...
show more
[26/Aug/2026:10:52:00 +0300] 178773072086.891735 2a03:2880:f814:36:: 57188 2a01:4f8:202:41d3::2 443
[26/Aug/2026:11:18:04 +0300] 17877322845.189416 2a03:2880:f814:36:: 58174 2a01:4f8:202:41d3::2 443
show less
Web App Attack
π©πͺ
jbcrn
2026-08-24 11:43:20
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Other, ruleset: ai.robots.txt. Requeste ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Other, ruleset: ai.robots.txt. Requested honeypot path: /fediverse/post/deflagration.mima-bougar/sparrowish-adelomorphous/Chalybean-blusteration/Toucanid/afterswell/cornettist/. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
show less
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-08-22 18:01:51
(1 week ago)
L7 DDoS: hammering a site's endpoints (login page, AJAX, dynamic pages) with automated requests far ...
show more
L7 DDoS: hammering a site's endpoints (login page, AJAX, dynamic pages) with automated requests far beyond any human use | path: /calendrier-2/action~agenda/cat_ids~142/tag_ids~725,437,331,559,403,264,493,681,343,471,235,435/request_format~json/
show less
DDoS Attack
Web App Attack
π§π·
alcacerlab
2026-08-22 16:49:54
(1 week ago)
2a03:2880:f814:36:: - - [22/Aug/2026:13:49:52 -0300] "GET / HTTP/2" 200 54774 "-" "facebookexternalh ...
show more
2a03:2880:f814:36:: - - [22/Aug/2026:13:49:52 -0300] "GET / HTTP/2" 200 54774 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 18:30:05
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f814:36:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f814:36:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 14:29:57.552273 2026] [security2:error] [pid 13279:tid 13291] [client 2a03:2880:f814:36:::60482] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||charliefranks.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "charliefranks.com"] [uri "/charliefranks.com"] [unique_id "aodHpWXVNGyUnEFHmYEYdwAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-18 22:22:28
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jira.goblinpot.site | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-18 16:20:34
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cloud.teddypot.pro | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2026-08-18 14:44:49
(2 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /categoria/fechaduras-residenciais/fechaduras-eletricas/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot