๐ต๐ฑ
Budyn
2026-08-16 08:44:21
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.site | URI: / | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.0) Gecko/20100101 Firefox/128.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-08-15 16:40:24
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.site | URI: / | UA: Mozilla/5.0 (Kubuntu; Linux i686; rv:126.0) Gecko/20100101 Firefox/126.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-08-13 09:56:32
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: definitelynotahoneypot.xyz | URI: / | UA: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-07-29 05:10:22
(2 months ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: URI: / | UA: Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-07-28 18:00:33
(2 months ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: URI: / | UA: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
Charlesiv
2026-03-17 00:04:11
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: BLOCK
ASN: 16276 (OVH)
Protocol: HT ...
show more
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: BLOCK
ASN: 16276 (OVH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-03-17T00:03:08Z
Ray ID: 9dd7bb9a1df7bb7c
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/29.0 Chrome/136.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Anonymous
2026-03-16 09:25:05
(6 months ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ซ๐ท
Bensay
2026-03-15 11:48:39
(6 months ago)
[Sun Mar 15 11:49:45.001642 2026] [authz_core:error] [pid 257761:tid 257833] [client 51.254.204.161: ...
show more
[Sun Mar 15 11:49:45.001642 2026] [authz_core:error] [pid 257761:tid 257833] [client 51.254.204.161:33894] AH01630: client denied by server configuration: /var/www/empty/
[Sun Mar 15 12:48:38.863967 2026] [authz_core:error] [pid 257762:tid 257824] [client 51.254.204.161:39406] AH01630: client denied by server configuration: /var/www/empty/
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
Roper123
2026-03-15 03:08:47
(6 months ago)
Web app exploits
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-03-15 03:05:54
(6 months ago)
51.254.204.161 - - [15/Mar/2026:03:05:51 +0000] "GET / HTTP/1.0" 200 5600 "-" "Mozilla/5.0 (iPhone; ...
show more
51.254.204.161 - - [15/Mar/2026:03:05:51 +0000] "GET / HTTP/1.0" 200 5600 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 26_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 Safari/604.1 musical_ly_43.8.0 BytedanceWebview/d8a21c6"
...
show less
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-03-15 02:46:38
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 51.254.204.161 (FR/France/vps-bc373d ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 51.254.204.161 (FR/France/vps-bc373d38.vps.ovh.net): 1 in the last 3600 secs
show less
Web App Attack
๐ซ๐ฎ
wpwoodo
2026-03-14 23:38:44
(6 months ago)
Webpage crawler
Bad Web Bot
๐ฌ๐ง
poundawebsiteltd
2026-03-14 22:28:09
(6 months ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 51.254.204.161 - - [14/Mar/2026: ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 51.254.204.161 - - [14/Mar/2026:22:28:06 +0000] GET / HTTP/1.1 403 3035 - Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Mobile Safari/537.36
show less
Web App Attack
๐ซ๐ฎ
Jordy
2026-03-14 20:28:00
(6 months ago)
14/Mar/2026:21:22:44.544979 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
14/Mar/2026:21:22:44.544979 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 51.254.204.161] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "familievandemaat.nl"] [uri "/"] [unique_id "abXDlImDKrMbxb4wdD2HygAAAAQ"]
14/Mar/2026:21:22:44.544979 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 51.254.204.161] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/
...
show less
Web App Attack
Anonymous
2026-03-14 10:23:33
(6 months ago)
Malicious activity detected
Hacking
Web App Attack