🇵🇱
Budyn
2026-09-07 05:16:30
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.top | URI: /wp-admin/ | UA: Mozilla/5.0 (compatible; PublicWWWBot/1.0; +https://publicwww.com/bot.html) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 01:50:09
(1 day ago)
2a03:b0c0:1:e0::c00:8001 - - [07/Sep/2026:03:50:08 +0200] "GET / HTTP/1.1" 403 5824 "-" "Mozilla/5.0 ...
show more
2a03:b0c0:1:e0::c00:8001 - - [07/Sep/2026:03:50:08 +0200] "GET / HTTP/1.1" 403 5824 "-" "Mozilla/5.0 (compatible; PublicWWWBot/1.0; +https://publicwww.com/bot.html)" ...
show less
Web App Attack
🇵🇱
mscode.pl
2026-09-04 22:22:34
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC)
Protocol: HTTP/1.1 (GET method)
Zone: mscode.pl
Endpoint: /
UA: Mozilla/5.0 (compatible; PublicWWWBot/1.0; +https://publicwww.com/bot.html)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-23 05:05:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:05:29.945154 2026] [security2:error] [pid 25734:tid 25734] [client 2a03:b0c0:1:e0::c00:8001:47768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nextngnr.com"] [uri "/5xpfoU.htaccess"] [unique_id "aop_mYhWId9XiF1BD0FUIAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
claude CALVET
2026-08-08 16:27:25
(4 weeks ago)
gew-Joomla User : try to access forms...
Hacking
Anonymous
2026-07-25 22:26:01
(1 month ago)
2a03:b0c0:1:e0::c00:8001 - - [26/Jul/2026:00:25:59 +0200] "GET / HTTP/1.1" 403 5760 "-" "Mozilla/5.0 ...
show more
2a03:b0c0:1:e0::c00:8001 - - [26/Jul/2026:00:25:59 +0200] "GET / HTTP/1.1" 403 5760 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-07-13 18:22:52
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 14:22:47.053394 2026] [security2:error] [pid 2962:tid 2962] [client 2a03:b0c0:1:e0::c00:8001:47862] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||3ddatacenters.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3ddatacenters.com"] [uri "/3DAINews.com"] [unique_id "alUs97r5KzpcNCECCJ_VRAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-07-07 22:20:23
(2 months ago)
Multiple unauthorized connection attempts
Web App Attack
🇺🇸
TPI-Abuse
2026-07-05 08:46:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 04:45:54.906701 2026] [security2:error] [pid 23326:tid 23326] [client 2a03:b0c0:1:e0::c00:8001:46926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "needtoorder.us"] [uri "/USE-To-BLOCKwww.countryipblocks.net.htaccess"] [unique_id "akoZwgTNn5x2nCDzRVKbJAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-02 15:20:49
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 11:20:41.931661 2026] [security2:error] [pid 11654:tid 11654] [client 2a03:b0c0:1:e0::c00:8001:55914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tecnoconce.cl|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tecnoconce.cl"] [uri "/p-php.ini"] [unique_id "akaByfNz9m41MkoNjXdNSAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-06-24 12:31:25
(2 months ago)
Multiple unauthorized connection attempts
Web App Attack
🇺🇸
TPI-Abuse
2026-06-21 00:34:44
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 20:34:40.211321 2026] [security2:error] [pid 17843:tid 17843] [client 2a03:b0c0:1:e0::c00:8001:41276] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||accordionstars.com|F|2"] [data ".accordionfactory.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "accordionstars.com"] [uri "/www.accordionfactory.com"] [unique_id "ajcxoA_Rl4e-Tl7oGSZycAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-15 13:23:49
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 09:23:43.353918 2026] [security2:error] [pid 4285:tid 4285] [client 2a03:b0c0:1:e0::c00:8001:60784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||borzoi-pedigree.info|F|2"] [data ".webped.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "borzoi-pedigree.info"] [uri "/www.webped.com"] [unique_id "ai_833fDipnzzsJLRtH54AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Live Home Cams
2026-06-13 17:56:11
(2 months ago)
WebApp brute force attack detected. Multiple file scanning attempts from 2a03:b0c0:1:e0::c00:8001. D ...
show more
WebApp brute force attack detected. Multiple file scanning attempts from 2a03:b0c0:1:e0::c00:8001. Detected by fail2ban.
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-06-12 21:38:45
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:e0::c00:8001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 17:38:41.399783 2026] [security2:error] [pid 8417:tid 8417] [client 2a03:b0c0:1:e0::c00:8001:49714] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||caretakerspestcontrol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caretakerspestcontrol.com"] [uri "/JMRussell.com"] [unique_id "aix8YagtSdUwef8wAFPdhQAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack