๐ต๐ฑ
Budyn
2026-10-01 17:35:18
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: shop.budyn.ovh | URI: /dist/.vite/manifest.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-10-01 15:54:02
(6 days ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-10-01 15:23:34
(6 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 15:21:56
(6 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
mrcrassi
2026-10-01 14:12:09
(6 days ago)
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /api
UA: Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ต๐ฑ
lns.bz
2026-10-01 12:36:59
(6 days ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ต๐ฑ
Budyn
2026-10-01 11:52:58
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: billing.budyn.ovh | URI: /dist/.vite/manifest.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-10-01 10:51:53
(6 days ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /actuator/gateway/routes [RATE LIMITED - 1800s quarantin ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /actuator/gateway/routes [RATE LIMITED - 1800s quarantine] | Pays: BR | UA: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)
show less
Hacking
Web App Attack
๐บ๐ธ
Epimetheus
2026-10-01 10:46:29
(6 days ago)
Zombie network / Bot scanner detected:
[POST] /langflow/api/v1/validate/code
[POST] /api/designer/v ...
show more
Zombie network / Bot scanner detected:
[POST] /langflow/api/v1/validate/code
[POST] /api/designer/v1/file-content
[POST] /index.php
[POST] /read-document
[GET] /elmah.axd
[GET] /console
[GET] /runtime-config.js
[GET] /gcp-credentials.json
[GET] /.ssh/config
[GET] /services/.env
[GET] /_image
[GET] /appsettings.Development.json
[GET] /@fs/var/run/secrets/kubernetes.io/serviceaccount/token
[GET] /@fs/home/ubuntu/.aws/credentials
[GET] /telescope/requests
[GET] /model/info
[GET] /server.key
UA: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)
show less
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:26:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.188.247 (247.188.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.188.247 (247.188.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:26:28.982918 2026] [security2:error] [pid 1311:tid 1311] [client 34.39.188.247:53094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.qu1ck.com"] [uri "/images../.env"] [unique_id "ar41VMS6BReNcL7wXsxbBgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-10-01 09:57:07
(6 days ago)
Scan of vulnerable files
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-10-01 09:11:04
(6 days ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
Anonymous
2026-10-01 08:49:38
(6 days ago)
Aggressive web scan
Web App Attack
๐ฎ๐น
VHosting
2026-10-01 08:45:03
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 08:43:27
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.188.247 (247.188.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.188.247 (247.188.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 04:43:19.965761 2026] [security2:error] [pid 26302:tid 26302] [client 34.39.188.247:43008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mjsom.afjm.net"] [uri "/.htpasswd"] [unique_id "ar4dJ4y0CLXNV4IOZp0qUgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack