π©πͺ
LRob
2026-10-05 20:38:08
(5 days ago)
Repeated forbidden requests | method: GET | path: /1/controle-dacces-ipevia/1595944/formipevian1n2-f ...
show more
Repeated forbidden requests | method: GET | path: /1/controle-dacces-ipevia/1595944/formipevian1n2-formation-ipevia-niveau-1-2/registration, /0/interphonie-xellip/1323286/formxen1n2-formation-interphonie-ip-xellip-niveau-1-2/registration, /7/controle-dacces-intrusion-synchronic/1598993/formsynchrospe-formation-synchronic-indus-specialiste/registration (+2 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36
show less
Web App Attack
π©πͺ
Echobit
2026-10-05 07:12:01
(6 days ago)
Crawling, BadBot, Fake User-Agent, Ignore robots.txt
Hacking
Bad Web Bot
π΅π±
Budyn
2026-10-05 05:50:35
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.online | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-10-02 20:38:46
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.store | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
πΉπΌ
tyebstx
2026-09-29 20:10:29
(1 week ago)
Wazuh Alert Evidence: 31.76.60.162 - - [29/Sep/2026:20:10:27 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozi ...
show more
Wazuh Alert Evidence: 31.76.60.162 - - [29/Sep/2026:20:10:27 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-"
show less
Web App Attack
Anonymous
2026-09-26 06:54:41
(2 weeks ago)
Unauthorized access (80/tcp/http)
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 20:44:04
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 31.76.60.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.76.60.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:43:59.453774 2026] [security2:error] [pid 32176:tid 32176] [client 31.76.60.162:54754] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||caretakerspestcontrol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caretakerspestcontrol.com"] [uri "/JMRussell.com"] [unique_id "arWLj123TwvrS1VQF1mJigAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 07:53:30
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 31.76.60.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.76.60.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 03:53:23.264037 2026] [security2:error] [pid 29164:tid 29164] [client 31.76.60.162:51660] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||accordionstars.com|F|2"] [data ".accordionfactory.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "accordionstars.com"] [uri "/www.accordionfactory.com"] [unique_id "arDic6wmxlbW-_ywNd1hpgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-09-21 03:05:31
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.xyz | URI: /wp-admin/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 00:18:24
(3 weeks ago)
PAD: No_Ref detected
Bad Web Bot
π¨π
YF
2026-09-20 00:16:50
(3 weeks ago)
Malicious web activity confirmed β IP previously flagged as suspicious (automated re-check, score: 1 ...
show more
Malicious web activity confirmed β IP previously flagged as suspicious (automated re-check, score: 15%)
show less
Web App Attack
Anonymous
2026-09-19 22:55:02
(3 weeks ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2026-09-19 02:30:51
(3 weeks ago)
DDOS botnet activity
Web App Attack