๐ต๐ฑ
Budyn
2026-09-19 11:35:25
(8 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: k8s.astropot.space | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-18 21:50:24
(21 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
abuse-opdc
2026-09-18 20:50:46
(22 hours ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐ฌ๐ท
setupgr
2026-09-18 18:22:31
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 34.17.96.246 (IT/Italy/Piedmont/Turin/-/[AS39 ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.17.96.246 (IT/Italy/Piedmont/Turin/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 18 21:22:28.775926 2026] [security2:error] [pid 473698:tid 473790] [client 34.17.96.246:46732] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 246.96.17.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "doityourself.gr"] [uri "/"] [unique_id "aq2BZEe-pVA30IEuJ-GirQAABIM"]
show less
Port Scan
๐บ๐ธ
dot.mg
2026-09-18 18:20:05
(1 day ago)
Bad behaviour
Web Spam
๐บ๐ธ
TPI-Abuse
2026-09-18 17:14:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.96.246 (246.96.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.96.246 (246.96.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 13:14:09.708076 2026] [security2:error] [pid 1476:tid 1476] [client 34.17.96.246:40598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dojaservices.com"] [uri "/.git/config"] [unique_id "aq1xYWdhjWNeosWdQnn2tgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-09-18 17:03:53
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 34.17.96.246 (IT/Italy/Piedmont/Turin/-/[AS39 ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.17.96.246 (IT/Italy/Piedmont/Turin/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 18 20:03:48.786185 2026] [security2:error] [pid 473642:tid 473757] [client 34.17.96.246:37302] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 246.96.17.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "doityourself.gr"] [uri "/"] [unique_id "aq1u9E7wYV1K07AfCkHJVAAAAwg"]
show less
Port Scan
๐ซ๐ท
masterguru
2026-09-18 15:50:09
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-18 15:50:06
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-18 15:48:58
(1 day ago)
34.17.96.246 - - [18/Sep/2026:17:48:54 +0200] "GET /.env.remote HTTP/1.1" 403 549 "-" "Mozilla/5.0 ( ...
show more
34.17.96.246 - - [18/Sep/2026:17:48:54 +0200] "GET /.env.remote HTTP/1.1" 403 549 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.96.246 - - [18/Sep/2026:17:48:54 +0200] "GET /.env.bak HTTP/1.1" 403 549 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.96.246 - - [18/Sep/2026:17:48:54 +0200] "GET /.env.backup HTTP/1.1" 403 549 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.96.246 - - [18/Sep/2026:17:48:54 +0200] "GET /.env.save HTTP/1.1" 403 549 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.96.246 - - [18/Sep/2026:17:48:54 +0200] "GET /.env.old HTTP/1.1" 403 549 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.96.246 - - [18/Sep/2026:17:48:54 +0200] "GET /.env.s
show less
Web App Attack
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-09-18 15:27:23
(1 day ago)
[18/Sep/2026:18:27:22 +0300] -- 34.17.96.246 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[18/Sep/2026:18:27:22 +0300] -- 34.17.96.246 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-18 13:30:18
(1 day ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-18 10:03:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.96.246 (246.96.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.96.246 (246.96.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:03:20.525766 2026] [security2:error] [pid 29961:tid 29961] [client 34.17.96.246:46474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dinsbach.net"] [uri "/.git/config"] [unique_id "aq0MaJGRAJFVC7eB9gRSiAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 08:04:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.96.246 (246.96.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.96.246 (246.96.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 04:04:19.957509 2026] [security2:error] [pid 15182:tid 15182] [client 34.17.96.246:48054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dinogirl.com"] [uri "/.git/config"] [unique_id "aqzwg3J1aRkr5Zjgf6EYPwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Halux
2026-09-18 07:11:40
(1 day ago)
34.17.96.246 Probing protected path or service
Web App Attack