๐ต๐ฑ
Budyn
2026-09-24 08:16:57
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.budyn.ovh | URI: /dist/.vite/manifest.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-09-24 07:53:20
(3 hours ago)
8.229.57.3 - - [24/Sep/2026:03:53:20 -0400] "GET /pn2rose3p4pzqjvfr5lv HTTP/1.1" 401 703 "-" "Mozill ...
show more
8.229.57.3 - - [24/Sep/2026:03:53:20 -0400] "GET /pn2rose3p4pzqjvfr5lv HTTP/1.1" 401 703 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
Web App Attack
SSH
๐ต๐ฑ
Tankudoraiba
2026-09-24 06:04:22
(4 hours ago)
Suspicious 404 request: GET /.vite/manifest.json HTTP/2.0
Hacking
๐ต๐ฑ
Budyn
2026-09-24 03:57:51
(7 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.budyn.ovh | URI: /.vite/manifest.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ซ๐ท
regishoussin
2026-09-24 01:46:46
(9 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-24 01:46 UTC.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-24 01:07:38
(9 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 8.229.57.3 (US/United States/3.57.229.8. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 8.229.57.3 (US/United States/3.57.229.8.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 8.229.57.3 - - [24/Sep/2026:03:07:35 +0200] "GET /.aws/credentials HTTP/2.0" 429 41 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "8.229.57.3" host=ipv6.elektra.ovh
show less
Port Scan
๐ฉ๐ช
maxpower
2026-09-24 00:30:24
(10 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 8.229.57.3 (US/United States/3.57.229.8. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 8.229.57.3 (US/United States/3.57.229.8.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 8.229.57.3 - - [24/Sep/2026:02:30:18 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 200 12093 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" host=mail.elektra.ovh
show less
Port Scan
๐ฌ๐ง
Interceptor_HQ
2026-09-24 00:03:34
(10 hours ago)
request_uri: / -- automatic report --
Brute-Force
Hacking
๐ต๐ฑ
Budyn
2026-09-23 23:37:02
(11 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: node-pl.budyn.ovh | URI: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฉ๐ช
hmt
2026-09-23 22:06:52
(12 hours ago)
8.229.57.3 - - [24/Sep/2026:00:06:51 +0200] "GET /.env.save HTTP/2.0" 404 170 "-" "Mozilla/5.0 (Maci ...
show more
8.229.57.3 - - [24/Sep/2026:00:06:51 +0200] "GET /.env.save HTTP/2.0" 404 170 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" host="repo.hmt.ovh"
8.229.57.3 - - [24/Sep/2026:00:06:51 +0200] "GET /.env.prod HTTP/2.0" 404 107 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" host="repo.hmt.ovh"
8.229.57.3 - - [24/Sep/2026:00:06:51 +0200] "GET /api/.env HTTP/2.0" 404 107 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" host="repo.hmt.ovh"
8.229.57.3 - - [24/Sep/2026:00:06:51 +0200] "GET /.env.old HTTP/2.0" 404 107 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" host="repo.hmt.ovh"
8.229.57.3 - - [24/Sep/2026:00:06:51 +0200] "GET /admin/.env HTTP/2.0" 404 107 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bo
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-23 20:40:59
(14 hours ago)
{"level":"info","ts":1790196054.8234603,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790196054.8234603,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"8.229.57.3","remote_port":"32912","client_ip":"8.229.57.3","proto":"HTTP/2.0","method":"GET","host":"status.altercampagne.ovh","uri":"/dist/manifest.json","headers":{"Accept-Encoding":["gzip, deflate, br, zstd"],"X-Nextjs-Data":["1"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-User":["?1"],"Sec-Ch-Ua-Mobile":["?0"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Fetch-Site":["none"],"Sec-Fetch-Mode":["navigate"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middle
...
show less
DDoS Attack
Web App Attack
๐ต๐ฑ
Budyn
2026-09-23 19:25:06
(15 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: vpn.budyn.ovh | URI: /api/.env/public/.env | UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ซ๐ท
Lino Project
2026-09-23 19:24:53
(15 hours ago)
8.229.57.3 - - [23/Sep/2026:21:24:51 +0200] "GET /user/login HTTP/1.1" 404 403 "-" "Mozilla/5.0 (Lin ...
show more
8.229.57.3 - - [23/Sep/2026:21:24:51 +0200] "GET /user/login HTTP/1.1" 404 403 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0"
8.229.57.3 - - [23/Sep/2026:21:24:51 +0200] "GET /admin HTTP/1.1" 404 403 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Nop Nop
2026-09-23 19:23:51
(15 hours ago)
CrowdSec ban: crowdsecurity/http-probing
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-23 18:52:03
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.57.3 (3.57.229.8.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.57.3 (3.57.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:51:55.653603 2026] [security2:error] [pid 14659:tid 14659] [client 8.229.57.3:44052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wildcroc.us"] [uri "/.env"] [unique_id "arQfy5Dn5-_BkhVg6ACVVQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack