๐ต๐ฑ
Budyn
2026-09-09 03:04:34
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.definitelynotahoneypot.top | URI: /backup.sql | UA: Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.7922.173 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Trashware
2026-08-25 03:39:53
(4 weeks ago)
Nosy troll bot
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-18 09:19:36
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: mail.teddypot.website | URI: /backup.sql | UA: Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.7922.137 Mobile Safari/537.36 (compatible; GoogleOther) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-08 00:39:59
(1 month ago)
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 66.249.75.104 - - [08/Aug/2026:03:39:58 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 66.249.75.104 - - [08/Aug/2026:03:39:58 +0300] "GET /solr/ HTTP/1.1" 404 6237 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.7871.186 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-05 21:20:45
(1 month ago)
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 66.249.75.104 - - [06/Aug/2026:00:20:44 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 66.249.75.104 - - [06/Aug/2026:00:20:44 +0300] "GET /solr/ HTTP/1.1" 404 6237 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.7871.186 Mobile Safari/537.36 (compatible; GoogleOther)"
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-31 05:50:18
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2026-07-31 05:35:02
(1 month ago)
2026/07/31 07:35:01 [error] 42202#158827: *67808 limiting requests, excess: 0.987 by zone "crawler", ...
show more
2026/07/31 07:35:01 [error] 42202#158827: *67808 limiting requests, excess: 0.987 by zone "crawler", client: 66.249.75.104, server: ipariapro.hu, request: "GET / HTTP/1.1", host: "ipariapro.hu"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-03 12:18:03
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 66.249.75.104 (crawl-66-249-75-104.googlebot.co ...
show more
(mod_security) mod_security (id:210730) triggered by 66.249.75.104 (crawl-66-249-75-104.googlebot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 08:17:56.334943 2026] [security2:error] [pid 28354:tid 28354] [client 66.249.75.104:48922] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||21north.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "21north.com"] [uri "/base/install/index.php.bak"] [unique_id "akeodOovgrDjw4jZA4paYAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-06-25 13:15:11
(2 months ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-06-22 16:37:08
(3 months ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 14:30:46
(3 months ago)
66.249.75.104 - - [20/Jun/2026:16:30:37 +0200] "GET /assets/libraries/jquery.autocomplete.min.js?v=2 ...
show more
66.249.75.104 - - [20/Jun/2026:16:30:37 +0200] "GET /assets/libraries/jquery.autocomplete.min.js?v=20220929045944 HTTP/1.1" 404 448 "http://www.malizganipchavula.com/index.html" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.7778.96 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.75.104 - - [20/Jun/2026:16:30:37 +0200] "GET /assets/libraries/jquery.autocomplete.min.js?v=20220929045944 HTTP/1.1" 404 252 "http://www.malizganipchavula.com/index.html" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.7778.96 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.75.104 - - [20/Jun/2026:16:30:38 +0200] "GET /assets/js/vendor/chosen.jquery.js?v=20240718033249 HTTP/1.1" 404 448 "http://www.malizganipchavula.com/index.html" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/5
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 21:58:52
(3 months ago)
(mod_security) mod_security (id:213060) triggered by 66.249.75.104 (crawl-66-249-75-104.googlebot.co ...
show more
(mod_security) mod_security (id:213060) triggered by 66.249.75.104 (crawl-66-249-75-104.googlebot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 17:58:49.031371 2026] [security2:error] [pid 9801:tid 9801] [client 66.249.75.104:46518] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)((?:\\\\bx(?:link:href|html|mlns)|!ENTITY\\\\b.{0,399}?\\\\b(?:SYSTEM|PUBLIC)|\\\\bdata:text\\\\/html))" at ARGS:_bd_prev_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "170"] [id "213060"] [rev "7"] [msg "COMODO WAF: XSS Filter - Category 3: Attribute Vector||mediatvplus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "mediatvplus.com"] [uri "/pages.php"] [unique_id "ajRqGfkdIjHADTPk10W_IAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-06-15 14:08:17
(3 months ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-06-07 13:35:19
(3 months ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2026-05-21 15:58:14
(4 months ago)
UFW:High-frequency access to non-released ports used by software with known vulnerabilities.
Port Scan