Anonymous
2026-09-10 08:42:54
(1 month ago)
fail2ban: Sensitive web probes detected
Web App Attack
๐ต๐ฑ
Budyn
2026-09-10 08:41:48
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.definitelynotahoneypot.online | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
seanwall
2026-09-10 08:35:43
(1 month ago)
Automated scanner/attacker probing war-room. Paths: ['/.git/config', '/.env']. UA: ['Mozilla/5.0 (X1 ...
show more
Automated scanner/attacker probing war-room. Paths: ['/.git/config', '/.env']. UA: ['Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36']
show less
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-10 07:43:51
(1 month ago)
20 attempts against mh-misbehave-ban on star
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-10 07:08:55
(1 month ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-10 06:39:23
(1 month ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ช
cmbplf
2026-09-10 06:08:29
(1 month ago)
61.641 requests in 1 hour (1mo2w6d)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-10 06:07:37
(1 month ago)
20 attempts against mh-misbehave-ban on melon
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 05:55:03
(1 month ago)
Bot / scanning and/or hacking attempts: GET /transactional/.env HTTP/1.1, GET /mailjet/.env HTTP/1.1 ...
show more
Bot / scanning and/or hacking attempts: GET /transactional/.env HTTP/1.1, GET /mailjet/.env HTTP/1.1, GET /php.php HTTP/1.1, GET /phpinfo HTTP/1.1, GET /debug.php HTTP/1.1, GET /i.php HTTP/1.1, GET /mandrill/.env HTTP/1.1, GET /pinfo.php HTTP/1.1, GET /info.php HTTP/1.1, GET /test.php HTTP/1.1, GET /bulk/.env HTTP/1.1, GET /admin/phpinfo.php HTTP/1.1, GET /p.php HTTP/1.1, GET /phpinfo.php HTTP/1.1, GET /pi.php HTTP/1.1, GET /brevo/.env HTTP/1.1, GET /sendgrid/.env HTTP/1.1, GET /postmark/.env HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 04:02:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.89.212.18 (18.212.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.212.18 (18.212.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 00:02:34.466729 2026] [security2:error] [pid 3683:tid 3683] [client 34.89.212.18:44146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehiddengemmalta.com"] [uri "/.git/config"] [unique_id "aqIr2lYkHNz39ghF_IqZxAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 01:23:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.89.212.18 (18.212.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.212.18 (18.212.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 21:23:51.041338 2026] [security2:error] [pid 10395:tid 10395] [client 34.89.212.18:38416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.seasidesolutions.org"] [uri "/.git/config"] [unique_id "aqIGp08TmW4xssEmxj37ZgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 00:19:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.89.212.18 (18.212.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.212.18 (18.212.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 20:19:28.649068 2026] [security2:error] [pid 12351:tid 12351] [client 34.89.212.18:53320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rhythmandbluescompany.com"] [uri "/.git/config"] [unique_id "aqH3kArLfyNs96Tfi2ZDuQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-10 00:13:22
(1 month ago)
Scanning for web/db/file exploits on rhythm.nl
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 23:40:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.89.212.18 (18.212.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.212.18 (18.212.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:40:50.758807 2026] [security2:error] [pid 22698:tid 22698] [client 34.89.212.18:56230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rhysryan.com"] [uri "/.git/config"] [unique_id "aqHugq96h9qhcgL6hBjTgAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-09 19:49:53
(1 month ago)
Web attack/malicious scanning detected
Web App Attack