๐ต๐ฑ
Budyn
2026-09-17 16:14:58
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.budyn.top | URI: /.env | UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-16 14:12:25
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.budyn.xyz | URI: /wp-admin | UA: Mozilla/5.0 (Linux; arm_64; Android 14; SM-A346E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.1012 YaSearchBrowser/24.125.1 BroPP/1.0 YaSearchApp/24.125.1 webOmni SA/3 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 10:03:47
(1 day ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /faq | 2026-09-16 10:03 UTC
show less
Bad Web Bot
๐ต๐ฑ
Budyn
2026-09-16 03:09:59
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: portal.astropot.website | URI: /xmlrpc.php | UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:01:55
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:01:46.679963 2026] [security2:error] [pid 18015:tid 18015] [client 47.79.206.98:31328] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.circleofsound.org|F|2"] [data ".cristalvibrasons.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.circleofsound.org"] [uri "/france/bordeaux/www.cristalvibrasons.com"] [unique_id "aqnASkXb4Gg2SiM0hZgU_QAAAA0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 02:07:36
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 22:07:31.412875 2026] [security2:error] [pid 13522:tid 13522] [client 47.79.206.98:7906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||twincitytn.com|F|2"] [data ".googletagmanager.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "twincitytn.com"] [uri "/ministries/sunday-school/www.googletagmanager.com"] [unique_id "aqioY9IWKaaMlsLSa7jvqgAAAAQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-14 20:06:03
(2 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /mechanomorphic-tersely. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
1gz
2026-09-14 14:17:05
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /showbiz/gjergj
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-14 02:00:26
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 22:00:20.792060 2026] [security2:error] [pid 1161:tid 1161] [client 47.79.206.98:34130] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||djbadger.com|F|2"] [data ".oldschooltechno.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "djbadger.com"] [uri "/www.oldschooltechno.com"] [unique_id "aqdVNPPCDS1KsHStF8jtvQAAABI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-09-13 21:30:01
(3 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-13 11:00:42
(4 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /actualite/semaine-hlm-lancement-coup-de-pouce-val-touraine-habitat | 2026-09-13 11:00 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-12 12:18:11
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:18:04.972907 2026] [security2:error] [pid 26139:tid 26139] [client 47.79.206.98:23702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mardensmith.com|F|2"] [data ".mardensmith.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mardensmith.com"] [uri "/wordpress/reportage/www.mardensmith.com"] [unique_id "aqVC_Gnj-bES33KJo1HT6wAAAD8"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-12 06:19:13
(5 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /category/histoire-odb-organisation-uniformes/histoire | 2026-09-12 06:19 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-12 00:10:04
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:09:55.582739 2026] [security2:error] [pid 6672:tid 6672] [client 47.79.206.98:15014] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.peterjohnsonauthor.com|F|2"] [data ".peterjohnsonauthor.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.peterjohnsonauthor.com"] [uri "/2016/08/www.peterjohnsonauthor.com"] [unique_id "aqSYUxurGJ_0Ouj3Oew6DAAAABo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-10 07:10:25
(1 week ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 68>=65, Abuse 67, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack