🇬🇧
consul.to
2026-09-06 21:23:51
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇵🇱
Budyn
2026-09-06 20:47:23
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: login.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-06 16:38:38
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: login.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-06 09:46:04
(2 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
DE/Germany/ec2-35-159-250-186.eu-central-1.compute ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
DE/Germany/ec2-35-159-250-186.eu-central-1.compute.amazonaws.com
show less
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 03:17:29
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇫🇷
dynamix
2026-09-06 01:40:04
(3 days ago)
Multiple WAF Violations
Web App Attack
🇫🇷
masterguru
2026-09-06 00:48:17
(3 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
its101
2026-09-05 19:00:53
(3 days ago)
Automated detection by LockdownAccess security system. Attack type(s): env_grab. Reason: Nginx: env_ ...
show more
Automated detection by LockdownAccess security system. Attack type(s): env_grab. Reason: Nginx: env_grab attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Web App Attack
🇩🇪
LRob
2026-09-05 16:21:00
(3 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+13 more) | 2026-09-05 16:21 UTC
show less
Hacking
Web App Attack
🇩🇪
hchristo
2026-09-05 10:31:05
(3 days ago)
[Sat Sep 05 12:31:04.768582 2026] [authz_core:error] [pid 40293:tid 40675] [client 35.159.250.186:59 ...
show more
[Sat Sep 05 12:31:04.768582 2026] [authz_core:error] [pid 40293:tid 40675] [client 35.159.250.186:59838] AH01630: client denied by server configuration: /var/www/kd1103/htdocs/fortunecafe.de/subdomains/localizer.fortunecafe.de/.env.bak
[Sat Sep 05 12:31:04.786353 2026] [authz_core:error] [pid 40293:tid 40662] [client 35.159.250.186:59838] AH01630: client denied by server configuration: /var/www/kd1103/htdocs/fortunecafe.de/subdomains/localizer.fortunecafe.de/.env.save
[Sat Sep 05 12:31:04.795639 2026] [authz_core:error] [pid 40293:tid 40580] [client 35.159.250.186:59838] AH01630: client denied by server configuration: /var/www/kd1103/htdocs/fortunecafe.de/subdomains/localizer.fortunecafe.de/.env.old
[Sat Sep 05 12:31:04.907814 2026] [authz_core:error] [pid 40293:tid 40702] [client 35.159.250.186:59838] AH01630: client denied by server configuration: /var/www/kd1103/htdocs/fortunecafe.de/subdomains/localizer.fortunecafe.de/.env.swp
[Sat Sep 05 12:31:04.916204 2026] [authz_core:error] [p
...
show less
Brute-Force
🇷🇴
clauss
2026-09-05 09:48:33
(3 days ago)
35.159.250.186 - - [05/Sep/2026:12:48:30 +0300] "GET /.git/config HTTP/2.0" 404 21349 "-" "Mozilla/5 ...
show more
35.159.250.186 - - [05/Sep/2026:12:48:30 +0300] "GET /.git/config HTTP/2.0" 404 21349 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.159.250.186 - - [05/Sep/2026:12:48:32 +0300] "GET /.env.local HTTP/2.0" 404 21349 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇯🇵
beon
2026-09-05 09:33:35
(3 days ago)
[DateTime=>2026-09-05T09:33:35Z to 2026-09-05T09:34:51Z (UTC)] , [HoneyPot_Hits=>250 times] , [Honey ...
show more
[DateTime=>2026-09-05T09:33:35Z to 2026-09-05T09:34:51Z (UTC)] , [HoneyPot_Hits=>250 times] , [HoneyPots=>/.git/config, /.env, /.env.local, /.env.production, /.env.staging, /.env.development and others] , [404targets=>/_environment, /phpinfo.php.bak, /phpinfo.php.old, /phpinfo.php~, /info.php.bak, /phpinfo.php.save] , [total_Hits=>261 times] , [hit_per_second=>3.43] , [Keyword=>WordPress, Joomla, Laravel]
show less
Bad Web Bot
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-03 21:55:12
(5 days ago)
Multiple WAF Violations
Web App Attack
🇫🇷
Octopuce
2026-09-03 14:08:25
(5 days ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
🇳🇱
Site.eu
2026-09-03 11:42:24
(5 days ago)
Excessive 404/403 errors
Brute-Force