🇺🇸
TPI-Abuse
2026-09-13 04:51:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:ca80:b00b:5ade::5 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:ca80:b00b:5ade::5 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 00:51:44.287330 2026] [security2:error] [pid 9419:tid 9419] [client 2a0f:ca80:b00b:5ade::5:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bradleybarefoot.com"] [uri "/.git/config"] [unique_id "aqYr4BbGfrJalv1CGb91BAAAAAs"], referer: http://bradleybarefoot.com/.git/config
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-13 02:36:05
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: beta.sweetpuddingtrap.online | URI: /.env.bak | UA: Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 23:36:30
(1 day ago)
CrowdSec: crowdsecurity/vpatch-env-access
Hacking
Web App Attack
🇵🇱
Budyn
2026-09-12 22:33:48
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: beta.goblinpot.online | URI: /.gitconfig | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-12 18:33:31
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: k8s.astropot.tech | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:133.0) Gecko/20100101 Firefox/133.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-12 14:04:10
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: beta.astropot.store | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.6 Safari/605.1.15 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-12 13:58:04
(1 day ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇵🇱
Budyn
2026-09-12 09:37:09
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: grafana.definitelynotahoneypot.online | URI: /phpinfo.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 09:33:22
(1 day ago)
Aggressive web scan
Bad Web Bot
Web App Attack
🇫🇷
HerrWolf
2026-09-12 09:00:03
(1 day ago)
CrowdSec Detection: crowdsecurity/http-probing
Web App Attack
🇫🇷
dynamix
2026-09-12 07:27:51
(1 day ago)
Multiple WAF Violations
Web App Attack
🇵🇱
alianet
2026-09-12 05:44:58
(2 days ago)
[Sat Sep 12 05:43:42.378399 2026] [proxy_fcgi:error] [pid 822081:tid 822163] [client 2a0f:ca80:b00b: ...
show more
[Sat Sep 12 05:43:42.378399 2026] [proxy_fcgi:error] [pid 822081:tid 822163] [client 2a0f:ca80:b00b:5ade::5:35318] AH01071: Got error 'Primary script unknown', referer: http://alianet.pl/phpinfo.php
[Sat Sep 12 05:43:42.384116 2026] [proxy_fcgi:error] [pid 822248:tid 822289] [client 2a0f:ca80:b00b:5ade::5:35338] AH01071: Got error 'Primary script unknown', referer: http://alianet.pl/info.php
[Sat Sep 12 05:43:42.401634 2026] [proxy_fcgi:error] [pid 822081:tid 822160] [client 2a0f:ca80:b00b:5ade::5:35318] AH01071: Got error 'Primary script unknown', referer: http://alianet.pl/config.php
[Sat Sep 12 05:43:42.406985 2026] [proxy_fcgi:error] [pid 822081:tid 822185] [client 2a0f:ca80:b00b:5ade::5:35326] AH01071: Got error 'Primary script unknown', referer: http://alianet.pl/wp-config.php
[Sat Sep 12 05:44:50.517226 2026] [proxy_fcgi:error] [pid 822248:tid 822278] [client 2a0f:ca80:b00b:5ade::5:21752] AH01071: Got error 'Primary script unknown', referer: http://alianet.pl/db.php
[Sat Sep 12
...
show less
Port Scan
Web App Attack
🇵🇱
Budyn
2026-09-12 05:36:00
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sql.goblinpot.tech | URI: /info.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇫🇷
Catalin Negru
2026-09-12 05:35:25
(2 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇵🇱
Budyn
2026-09-12 01:24:55
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: k8s.goblinpot.site | URI: /docker-compose.yml | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack