🇬🇧
Apache
2026-09-13 18:06:14
(15 minutes ago)
(mod_security) mod_security (id:930130) triggered by 3.111.113.199 (IN/India/ec2-3-111-113-199.ap-so ...
show more
(mod_security) mod_security (id:930130) triggered by 3.111.113.199 (IN/India/ec2-3-111-113-199.ap-south-1.compute.amazonaws.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇩🇪
iNetWorker
2026-09-13 15:19:29
(3 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇪🇪
Tsumugi Kotobuki
2026-09-13 13:31:55
(4 hours ago)
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 57 | Len: 60B | Win: ...
show more
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 57 | Len: 60B | Win: 62727(1) | rDNS: ec2-3-111-113-199.ap-south-1.compute.amazonaws.com | F2B/ufw-honeypot@2026-09-13T13:31:55Z
show less
Port Scan
Hacking
🇵🇱
Budyn
2026-09-13 12:32:22
(5 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: registry.budyn.xyz | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-13 12:08:06
(6 hours ago)
csagent: score 20.2: wp-config backup grab x2, 404 noise floor x2; 1 domain(s) in 6s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 11:59:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.111.113.199 (ec2-3-111-113-199.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.111.113.199 (ec2-3-111-113-199.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 07:59:08.279131 2026] [security2:error] [pid 18370:tid 18370] [client 3.111.113.199:36630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shhcenter.com"] [uri "/wp-config.php~"] [unique_id "aqaQDM20sXA_MPEJiGP1VwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-13 10:39:06
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 09:28:29
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.111.113.199 (ec2-3-111-113-199.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.111.113.199 (ec2-3-111-113-199.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:28:25.186225 2026] [security2:error] [pid 26438:tid 26438] [client 3.111.113.199:54036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonegym.com"] [uri "/wp-config.php.bak"] [unique_id "aqZsuXg6revZiQgfAr4W7AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 07:01:52
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.111.113.199 (ec2-3-111-113-199.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.111.113.199 (ec2-3-111-113-199.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:01:45.519601 2026] [security2:error] [pid 649483:tid 649483] [client 3.111.113.199:38062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troop9weymouth.com"] [uri "/wp-config.php.save"] [unique_id "aqZKWQOnHZIUDL86C0SGiQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-13 06:00:01
(12 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇳🇱
Alt255
2026-09-13 04:34:39
(13 hours ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 3.111.113.199 - - [13/Sep/2026:06:34:38 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 29187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-13 04:32:53
(13 hours ago)
Many_bad_calls
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 02:22:19
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.111.113.199 (ec2-3-111-113-199.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.111.113.199 (ec2-3-111-113-199.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 22:22:15.067526 2026] [security2:error] [pid 31974:tid 31974] [client 3.111.113.199:50332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fgrotary.org"] [uri "/wp-config.php.bak"] [unique_id "aqYI11JkZonNQuukDlmlWgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-13 01:04:24
(17 hours ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 3.111.113.199 - - [13/Sep/2026:03:04:24 +0200] "GET /wp-config.php.save HTTP/1.1" 301 6182 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-12 23:37:45
(18 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-12 23:37 UTC
show less
Bad Web Bot