🇩🇪
Philister11
2026-09-08 00:14:40
(2 minutes ago)
CrowdSec: crowdsecurity/http-sensitive-files (CH/AS396982)
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-07 23:56:35
(20 minutes ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
homeshowdomain.nl
2026-09-07 22:03:28
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇩🇪
Savvii
2026-09-07 22:00:50
(2 hours ago)
20 attempts against mh-misbehave-ban on train
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-07 21:37:51
(2 hours ago)
Automated abuse report: 15 attack/probe requests from Google LLC / CH.
Targeted paths: /.git/config, ...
show more
Automated abuse report: 15 attack/probe requests from Google LLC / CH.
Targeted paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging.
Sample log lines:
[signerauthority] 34.65.227.21 - - [07/Sep/2026:14:37:50 -0700] "GET /.env.example HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safar…
[signerauthority] 34.65.227.21 - - [07/Sep/2026:14:37:50 -0700] "GET /.env.dev HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/53…
[signerauthority] 34.65.227.21 - - [07/Sep/2026:14:37:51 -0700] "GET /.env.prod HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/5…
Detected by an automated web-server log monitor.
show less
Web App Attack
Anonymous
2026-09-07 21:27:26
(2 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-07 21:07:15
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇵🇱
Budyn
2026-09-07 16:31:01
(7 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: shop.definitelynotahoneypot.xyz | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇫🇮
mnazibo
2026-09-07 13:00:27
(11 hours ago)
Date: Sep 07 15:33:11 2026 EAT | Reported IP: 34.65.227.21 mod_security | id: 932130 932235 932260 9 ...
show more
Date: Sep 07 15:33:11 2026 EAT | Reported IP: 34.65.227.21 mod_security | id: 932130 932235 932260 933135 934100 934130 942151 942550 949110 930130 920440 920500 | CH/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Direct Unix Command Execution; Remote Command Execution: Direct Unix Command Execution; PHP Injection Attack: Variable Access Found; PHP Injection Attack: Variable Access Found; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection
show less
SQL Injection
Brute-Force
Bad Web Bot
🇺🇸
daveoctober
2026-09-07 12:48:23
(11 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
🇺🇸
CollideTech
2026-09-07 11:43:40
(12 hours ago)
probing for vulnerabilities
Web App Attack
🇨🇦
Anytech
2026-09-07 10:42:00
(13 hours ago)
Blocked by ConnMonitor
Web App Attack
🇩🇪
raph
2026-09-07 09:07:18
(15 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-07 08:42:56
(15 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: shop.budyn.ovh | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 07:37:54
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack