๐บ๐ธ
TPI-Abuse
2026-10-04 06:09:06
(51 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.234.214.113 (113.214.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.214.113 (113.214.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 02:09:02.803513 2026] [security2:error] [pid 2546:tid 2546] [client 8.234.214.113:41014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/composer.lock" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.plaisance.us"] [uri "/composer.lock"] [unique_id "asHtfga6n83JRlDgqH4HmgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-04 05:22:15
(1 hour ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: beta.teddypot.cloud | URI: /backend/.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-10-03 08:13:10
(22 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dev.teddypot.site | URI: /.env.old | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 03:09:56
(2 days ago)
[ti-hosboov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: ...
show more
[ti-hosboov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 8.234.214.113 - - \[02/Oct/2026:05:09:49 +0200\] "GET /wp-config.php.bak HTTP/1.1" 404 7186 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 00:03:39
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ต๐ฑ
Budyn
2026-10-01 15:50:54
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.teddypot.tech | URI: /.git/HEAD | UA: Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-30 23:36:30
(3 days ago)
[ThuOct0101:36:26.4426982026][security2:error][pid2875252:tid2875254][client8.234.214.113:0]ModSecur ...
show more
[ThuOct0101:36:26.4426982026][security2:error][pid2875252:tid2875254][client8.234.214.113:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"partnersat.ch.81-17-25-250.cpanel.site\"][uri\"/.env.old\"][unique_id\"ar2c-nNu0R6myS6LBHJzsgAAAAA\"]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-09-26 02:15:29
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: test.teddypot.website | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-09-18 00:32:49
(2 weeks ago)
8.234.214.113 - - [18/Sep/2026:03:32:47 +0300] "POST / HTTP/1.1" 404 153 "-" "Python/3.10 aiohttp/3. ...
show more
8.234.214.113 - - [18/Sep/2026:03:32:47 +0300] "POST / HTTP/1.1" 404 153 "-" "Python/3.10 aiohttp/3.14.3"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 14:02:05
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.234.214.113 (113.214.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.214.113 (113.214.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:01:58.262315 2026] [security2:error] [pid 13687:tid 13687] [client 8.234.214.113:53148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healthpointphysicians.co"] [uri "/.git/config"] [unique_id "aqAVVjbwz7wJJVhd6WBlEAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-09-08 13:47:40
(3 weeks ago)
env leak on 401.today/api/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐ซ๐ท
Octopuce
2026-09-08 12:55:18
(3 weeks ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฉ๐ช
Admins@FBN
2026-09-08 06:04:07
(3 weeks ago)
FW-PortScan: Traffic Blocked srcport=33728 dstport=443
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-08 01:57:41
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.234.214.113 (113.214.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.214.113 (113.214.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:57:35.949716 2026] [security2:error] [pid 19947:tid 19973] [client 8.234.214.113:48218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3stepreviewforyou.com"] [uri "/.git/config"] [unique_id "ap9rj0lndQTlJMa-vjxY4gAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-08 00:55:57
(3 weeks ago)
Multiple WAF Violations
Web App Attack