๐ต๐ฑ
Budyn
2026-09-11 18:24:18
(29 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: s3.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
tsZero
2026-09-11 18:17:56
(36 minutes ago)
Scan example: path=/.git/config status=400
Hacking
๐ฉ๐ช
LRob
2026-09-11 06:50:51
(12 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-11 06:50 UTC
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-09-11 06:02:59
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 05:44:55
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.147.244 (244.147.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.147.244 (244.147.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:44:50.105086 2026] [security2:error] [pid 32541:tid 32541] [client 34.39.147.244:51924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "openid.rimbey.us"] [uri "/.git/config"] [unique_id "aqOVUvmaqu7tW4glp5-9lQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-11 05:35:34
(13 hours ago)
34.39.147.244 - - [11/Sep/2026:15:35:30 +1000] "GET /.git/config HTTP/1.1" 404 992 "-" "Mozilla/5.0 ...
show more
34.39.147.244 - - [11/Sep/2026:15:35:30 +1000] "GET /.git/config HTTP/1.1" 404 992 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.39.147.244 - - [11/Sep/2026:15:35:32 +1000] "GET /.env HTTP/1.1" 404 992 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.39.147.244 - - [11/Sep/2026:15:35:32 +1000] "GET /.env.local HTTP/1.1" 404 992 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.39.147.244 - - [11/Sep/2026:15:35:33 +1000] "GET /.env.production HTTP/1.1" 404 992 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.39.147.244 - - [11/Sep/2026:15:35:33 +1000] "GET /.env.staging HTTP/1.1" 404 992 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.39.147.244 - - [11/Sep/2026:15:35:33 +1000] "
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-11 04:47:33
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.147.244 (244.147.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.147.244 (244.147.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:47:27.376293 2026] [security2:error] [pid 30246:tid 30246] [client 34.39.147.244:36132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "openheartwellness.com"] [uri "/.git/config"] [unique_id "aqOH38SZViixSBfhgV9R2QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
abuse-opdc
2026-09-11 02:51:02
(16 hours ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-11 00:33:53
(18 hours ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
Francisco Vallejo
2026-09-10 20:40:11
(22 hours ago)
[Thu Sep 10 22:40:10.576476 2026] [authz_core:error] [pid 191767:tid 133111966852800] [client 34.39. ...
show more
[Thu Sep 10 22:40:10.576476 2026] [authz_core:error] [pid 191767:tid 133111966852800] [client 34.39.147.244:57864] AH01630: client denied by server configuration: proxy:http://giedi:3000/
[Thu Sep 10 22:40:10.781716 2026] [authz_core:error] [pid 191767:tid 133111958460096] [client 34.39.147.244:57864] AH01630: client denied by server configuration: proxy:http://giedi:3000/
[Thu Sep 10 22:40:10.981422 2026] [authz_core:error] [pid 191767:tid 133113663448768] [client 34.39.147.244:57864] AH01630: client denied by server configuration: proxy:http://giedi:3000/
[Thu Sep 10 22:40:11.181357 2026] [authz_core:error] [pid 191767:tid 133113585858240] [client 34.39.147.244:57864] AH01630: client denied by server configuration: proxy:http://giedi:3000/
[Thu Sep 10 22:40:11.380115 2026] [authz_core:error] [pid 191767:tid 133113569072832] [client 34.39.147.244:57864] AH01630: client denied by server configuration: proxy:http://giedi:3000/.git/config
...
show less
Brute-Force
SSH
๐บ๐ธ
daveoctober
2026-09-10 20:23:21
(22 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 15:03:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.147.244 (244.147.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.147.244 (244.147.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:03:17.033545 2026] [security2:error] [pid 17921:tid 17921] [client 34.39.147.244:41912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pioneercanadian.com"] [uri "/.git/config"] [unique_id "aqLGtXx9QZBdz70KAHWQlAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-10 13:32:51
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-10 13:09:08
(1 day ago)
20 attempts against mh-misbehave-ban on pinto
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-10 11:41:34
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack