๐ง๐พ
anan17
2026-09-16 05:39:39
(4 days ago)
Aggressive reconnaissance scanning for .env secrets, SSH keys, and config files using rotating spoof ...
show more
Aggressive reconnaissance scanning for .env secrets, SSH keys, and config files using rotating spoofed bot User-Agents
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-16 02:40:34
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: auth.budyn.ovh | URI: /.aws/config | UA: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Secure Gatewayยฎ๏ธ
2026-09-15 22:00:38
(4 days ago)
Report By Secure Gateway Security Team: Potential CSRF Attack Detected
SQL Injection
๐บ๐ธ
ALSCOยฎ๏ธ
2026-09-15 22:00:38
(4 days ago)
Report By ALSCO Security Team: SQL Injection Attempt Detected
Hacking
๐ต๐ฑ
Budyn
2026-09-15 21:33:15
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.budyn.ovh | URI: /.vite/manifest.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ซ๐ฎ
tjs
2026-09-15 21:05:00
(4 days ago)
web attack
Hacking
Web App Attack
๐ซ๐ท
ACE-INFORMATIQUE.NC
2026-09-15 19:00:07
(4 days ago)
Web App Attack blocked by Fail2ban
Web App Attack
Anonymous
2026-09-15 15:34:36
(4 days ago)
PSCSERV WPSCAN 34.74.254.65
Bad Web Bot
Web App Attack
๐ง๐ช
holos.pt
2026-09-15 15:00:03
(5 days ago)
Blocked for Directory Traversal in query string: ../conf/conf.php
Web App Attack
๐ท๐ด
iulianh
2026-09-15 14:29:45
(5 days ago)
80,443
Brute-Force
SSH
Anonymous
2026-09-15 14:26:31
(5 days ago)
34.74.254.65 detected on srv01
Brute-Force
๐ฟ๐ฆ
vanderhost
2026-09-15 14:23:50
(5 days ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel.lo ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel.log via rule: /storage/logs
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-15 14:15:47
(5 days ago)
[server.tmg.gr] httpd-config-scan: sites=www.mastermind.gr; logs=/var/log/httpd/domains/tmg.gr.log; ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.mastermind.gr; logs=/var/log/httpd/domains/tmg.gr.log; samples=/appearance/../../.env | /appearance/../../proc/self/environ | /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 14:02:11
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.254.65 (65.254.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.254.65 (65.254.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:02:06.830803 2026] [security2:error] [pid 490:tid 490] [client 34.74.254.65:48160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||summithost.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "summithost.com"] [uri "/rclone.conf"] [unique_id "aqlP3n1YkUKleg87IxRjHQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
snhosting
2026-09-15 13:56:00
(5 days ago)
34.74.254.65 - - [15/Sep/2026:15:55:49 +0200] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 200 1606 "-" " ...
show more
34.74.254.65 - - [15/Sep/2026:15:55:49 +0200] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 200 1606 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.74.254.65 - - [15/Sep/2026:15:55:49 +0200] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/2.0" 200 1606 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.74.254.65 - - [15/Sep/2026:15:55:50 +0200] "GET /dashboard%2F.env HTTP/2.0" 200 1606 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.74.254.65 - - [15/Sep/2026:15:55:50 +0200] "GET /admin%2F.env HTTP/2.0" 200 1606 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.74.254.65 - - [15/Sep/2026:15:55:50 +0200] "GET /api%2F.env HTTP/2.0" 200 1606 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH