π¦πΉ
RenΓ© Hickersberger
2026-09-30 05:10:43
(19 hours ago)
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (X11; Linux x86_64) Apple ...
show more
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
π΅π±
Budyn
2026-09-30 04:55:59
(20 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: git.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 23:23:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.246.182.21 (21.182.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.182.21 (21.182.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 19:23:08.968317 2026] [security2:error] [pid 10275:tid 10328] [client 35.246.182.21:51116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.digital4z.com"] [uri "/.git/config"] [unique_id "arr23NIByaHKDUVjvs5jHQAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 06:24:11
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π³π±
Alt255
2026-09-28 03:25:36
(2 days ago)
[cb-02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.246.182.21 - - [28/Sep/2026:05:25:15 +0200] "GET /.env.txt HTTP/1.1" 404 14468 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
on-com
2026-09-27 05:35:32
(3 days ago)
URL scan
Brute-Force
Web App Attack
π¨π
zynex
2026-09-27 03:29:49
(3 days ago)
URL Probing: /core/.env
Web App Attack
π³π±
homeshowdomain.nl
2026-09-24 22:00:30
(6 days ago)
Auto-ban: >3000 req/min op 2026-09-24
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-24 18:35:05
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.246.182.21 (21.182.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.182.21 (21.182.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:34:59.835358 2026] [security2:error] [pid 309008:tid 309008] [client 35.246.182.21:51800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lightupaustralia.org"] [uri "/.git/config"] [unique_id "arVtU7Nt62HR392WQNz6BgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
jasperedv.de
2026-09-24 15:58:46
(6 days ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
π©πͺ
FD-IX
2026-09-24 14:31:00
(6 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-09-24 04:11:16
(6 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π³π±
homeshowdomain.nl
2026-09-23 22:01:30
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-21 23:43:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.246.182.21 (21.182.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.182.21 (21.182.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:43:08.485853 2026] [security2:error] [pid 24668:tid 24668] [client 35.246.182.21:40874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greenlight.us"] [uri "/.git/config"] [unique_id "arHBDMr44grMJJPrtzr5VAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 15:01:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.246.182.21 (21.182.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.182.21 (21.182.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:01:01.782261 2026] [security2:error] [pid 7911:tid 7911] [client 35.246.182.21:46366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "g-peopleland.com"] [uri "/.git/config"] [unique_id "arFGrU9zu0KT48MUHx75FwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack