๐ต๐ฑ
Budyn
2026-10-04 10:13:57
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: elastic.budyn.top | URI: /next/.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-10-04 05:28:43
(6 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: grafana.teddypot.website | URI: /.env.dev | UA: Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 12:04:17
(1 day ago)
[03/Oct/2026:12:04:16 +0000] host=mx1.lovelyrender.app server=_ ip=34.150.167.130 method=GET req=/.h ...
show more
[03/Oct/2026:12:04:16 +0000] host=mx1.lovelyrender.app server=_ ip=34.150.167.130 method=GET req=/.hermes/.env uri=/.hermes/.env status=301 bytes=162 rt=0.000 urt=- ref="-" ua="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-03 11:32:10
(1 day ago)
[cb-03al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-03al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.150.167.130 - - [03/Oct/2026:13:32:00 +0200] "GET /.env.compose HTTP/1.1" 301 463 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-03 11:00:07
(1 day ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ต๐ฑ
Budyn
2026-10-03 09:20:27
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: grafana.dont-eat-the-pudding.top | URI: /.doctl/config.yaml | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 05:12:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.150.167.130 (130.167.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.150.167.130 (130.167.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:12:20.228929 2026] [security2:error] [pid 1691:tid 1854] [client 34.150.167.130:36766] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jpdesign.us.jean-paullederer.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jpdesign.us.jean-paullederer.com"] [uri "/.oci/config.backup"] [unique_id "asCOtDNr1Opy__DnpX9iAAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-10-02 19:11:51
(1 day ago)
tcp/443 (28 or more attempts)
Port Scan
๐ธ๐ช
vaia.cloud
2026-10-02 05:20:02
(2 days ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-18 01:43:06
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Python/3.10 aiohttp/3.14.3
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-09-17 22:32:37
(2 weeks ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-09 06:00:01
(3 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Site.eu
2026-09-09 03:45:33
(3 weeks ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ช
cmbplf
2026-09-08 22:38:39
(3 weeks ago)
700 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ฉ๐ช
ger-stg-sifi1
2026-09-08 09:11:13
(3 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack