๐ต๐ฑ
Budyn
2026-08-27 11:20:15
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: / | UA: feroxbuster/2.13.1 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
pexodelic
2026-08-27 09:06:00
(1 day ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ณ๐ฟ
Antinson
2026-08-27 04:36:51
(2 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-27 03:53:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.229.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.229.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:53:22.275216 2026] [security2:error] [pid 2890:tid 2890] [client 34.34.229.11:18021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.45"] [uri "/.htaccessa48dcf1f9b4740a4885da3d40564cfc2"] [unique_id "ao-0siWqVV9hicP2TSbxowAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:14:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.229.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.229.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:14:04.564528 2026] [security2:error] [pid 1697:tid 1697] [client 34.34.229.11:53505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.198"] [uri "/.htaccess854d1794c26448cc812fdb94afa5ccfcd3d75a47f92a40729d8195f224733512dfca8aac0239447198876a6af69a7345"] [unique_id "ao-rfPLigVLgFcDh7uJxaAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xxkodedxx
2026-08-27 00:24:39
(2 days ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: US / AS396982 Google LLC
Active: 00:24:33 UTC
Volume: 1 HTTP req
Probed: /
Status mix: 444ร1
Vhost fishing: 67.217.240.72
UA: "Python-urllib/3.14"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-27 00:19:53
(2 days ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-08-26 21:22:46
(2 days ago)
[Wed Aug 26 23:22:45.626045 2026] [:error] [pid 1291730:tid 1291730] [client 34.34.229.11:1227] ModS ...
show more
[Wed Aug 26 23:22:45.626045 2026] [:error] [pid 1291730:tid 1291730] [client 34.34.229.11:1227] ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `scanners-user-agents.data' against variable `REQUEST_HEADERS:User-Agent' (Value: `feroxbuster/2.13.1' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "38"] [id "913100"] [rev ""] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: feroxbuster found within REQUEST_HEADERS:User-Agent: feroxbuster/2.13.1"] [severity "2"] [ver "OWASP_CRS/4.30.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/SCANNER-DETECTION"] [tag "capec/1000/118/224/541/310"] [uri "/"] [unique_id "178777936590.235475"] [ref "o0,11v39,18"]
...
show less
Web App Attack
๐ฏ๐ต
VXG-NET
2026-08-26 19:40:49
(2 days ago)
port=80, indicator_type=info-leak
Hacking
๐ณ๐ด
jad-abuse
2026-08-26 18:05:57
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, git_exposure. Observed by 1 sensor(s); 642 hits.
show less
Web App Attack
๐ฉ๐ช
Hary74656
2026-08-26 17:45:55
(2 days ago)
Fail2Ban on postler.hostmi.at: jail=apache-404, failures=30. No raw log data included.
Web App Attack
๐จ๐ญ
Zdenฤk Svancar
2026-08-26 16:22:08
(2 days ago)
34.34.229.11 - - [26/Aug/2026:16:22:06 +0000] "GET /admin HTTP/1.1" 404 146 "-" "feroxbuster/2.13.1" ...
show more
34.34.229.11 - - [26/Aug/2026:16:22:06 +0000] "GET /admin HTTP/1.1" 404 146 "-" "feroxbuster/2.13.1"
34.34.229.11 - - [26/Aug/2026:16:22:07 +0000] "GET /auth HTTP/1.1" 404 146 "-" "feroxbuster/2.13.1"
...
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-26 15:35:05
(2 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
Anonymous
2026-08-26 08:59:56
(2 days ago)
HTTP flood: excessive request rate against web ports. Detected and blocked automatically.
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 05:50:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.229.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.229.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:50:52.637306 2026] [security2:error] [pid 14876:tid 14900] [client 34.34.229.11:49271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.129"] [uri "/.htaccessc419dd5184e4468bad44a78992e3443bcda4d2570aaf4f95950520022c6cfdda76f57ce435a241a3ad866bc29a5fc7ee"] [unique_id "ao5-vNncmwp0nX6OhSASPwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack