🇭🇷
aktonrs
2026-08-31 05:42:37
(4 days ago)
Blocked by https://aegis.hr — Directory Traversal - (MITRE T1083), 313 attempts, Period: 2026-08-31 ...
show more
Blocked by https://aegis.hr — Directory Traversal - (MITRE T1083), 313 attempts, Period: 2026-08-31 05:21:58 to 2026-08-31 05:21:58
show less
Web App Attack
Hacking
🇵🇱
Budyn
2026-08-31 04:48:03
(4 days ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9b ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9br2dhw9iulptrg3dmcbkxl | Client Tool: Boto3/1.43.80 md/Botocore#1.43.80 ua/2.1 os/linux#6.12.94+deb13-cloud-amd64 md/arch#x86_64 lang/python#3.13.5 md/pyimpl#CPython m/D,e,N,b,Z cfg/retry-mode#le...
show less
Hacking
Bad Web Bot
Web App Attack
🇫🇮
6kilowatti
2026-08-31 04:09:26
(4 days ago)
2026-08-31T07:09:25.325687+03:00 6kw kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:16:3e:b6:e7:09:78:9a:18 ...
show more
2026-08-31T07:09:25.325687+03:00 6kw kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:16:3e:b6:e7:09:78:9a:18:bd:57:7e:08:00 SRC=81.27.101.113 DST=5.61.88.83 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=1043 DF PROTO=TCP SPT=29872 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
Port Scan
🇨🇿
gszasz
2026-08-31 03:44:39
(4 days ago)
81.27.101.113 - - [31/Aug/2026:05:44:38 +0200] "GET /api/fetch?url=http://[::ffff:169.254.169.254]/l ...
show more
81.27.101.113 - - [31/Aug/2026:05:44:38 +0200] "GET /api/fetch?url=http://[::ffff:169.254.169.254]/latest/meta-data/iam/security-credentials/ HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [31/Aug/2026:05:44:38 +0200] "GET /api/fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/ HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [31/Aug/2026:05:44:38 +0200] "GET /api/fetch?url=http://169.254.169.254.nip.io/latest/meta-data/iam/security-credentials/ HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
...
show less
Brute-Force
Web App Attack
🇫🇷
georgton.tech
2026-08-31 00:54:16
(4 days ago)
81.27.101.113 - - [30/Aug/2026:21:54:15 -0300] "GET /public/plugins/gauge/../../../../../../../root/ ...
show more
81.27.101.113 - - [30/Aug/2026:21:54:15 -0300] "GET /public/plugins/gauge/../../../../../../../root/.aws/credentials HTTP/1.1" 400 166 "-" "-"
81.27.101.113 - - [30/Aug/2026:21:54:15 -0300] "GET /public/plugins/heatmap/../../../../../../../var/lib/grafana/grafana.db HTTP/1.1" 400 166 "-" "-"
81.27.101.113 - - [30/Aug/2026:21:54:15 -0300] "GET /public/plugins/alertlist/../../../../../../../etc/passwd HTTP/1.1" 400 166 "-" "-"
...
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-30 12:26:53
(5 days ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9b ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_9 | Action: AWS API Call | Token: nk9br2dhw9iulptrg3dmcbkxl | Client Tool: Botocore/1.43.80 ua/2.1 os/linux#6.12.94+deb13-cloud-amd64 md/arch#x86_64 lang/python#3.13.5 md/pyimpl#CPython m/D,Z,b,e cfg/retry-mode#legacy
show less
Hacking
Bad Web Bot
Web App Attack
🇸🇰
Shadow77
2026-08-30 11:57:00
(5 days ago)
81.27.101.113 - - [30/Aug/2026:07:00:12 +0200] "GET /actuator/threaddump HTTP/1.1" 301 486 "-" "Mozi ...
show more
81.27.101.113 - - [30/Aug/2026:07:00:12 +0200] "GET /actuator/threaddump HTTP/1.1" 301 486 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [30/Aug/2026:07:00:12 +0200] "GET /actuator/metrics HTTP/1.1" 301 480 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [30/Aug/2026:07:00:12 +0200] "GET /actuator/mappings HTTP/1.1" 301 482 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [30/Aug/2026:07:00:12 +0200] "GET /fetch?url=http://0xa9fea9fe/latest/meta-data/iam/security-credentials/ HTTP/1.1" 301 588 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
show less
Brute-Force
Web App Attack
🇳🇱
Ilop
2026-08-30 04:33:56
(5 days ago)
[v6-22] Firewall dropped 4 unsolicited packet(s) proto=tcp to port(s) 80,443 from 81.27.101.113 — WA ...
show more
[v6-22] Firewall dropped 4 unsolicited packet(s) proto=tcp to port(s) 80,443 from 81.27.101.113 — WAN scan (automated sensor)
show less
Port Scan
🇳🇱
Ilop
2026-08-29 03:04:03
(6 days ago)
[v6-22] Firewall dropped 4 unsolicited packet(s) proto=tcp to port(s) 80,443 from 81.27.101.113 — WA ...
show more
[v6-22] Firewall dropped 4 unsolicited packet(s) proto=tcp to port(s) 80,443 from 81.27.101.113 — WAN scan (automated sensor)
show less
Port Scan
🇪🇸
el-brujo
2026-08-28 15:14:01
(6 days ago)
28/Aug/2026:17:14:01.237682 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Aug/2026:17:14:01.237682 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 81.27.101.113] ModSecurity: Warning. Pattern match "^(?i:file|ftps?|https?):\\\\\\\\/\\\\\\\\/(?:\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3})" at ARGS:url. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf"] [line "56"] [id "931100"] [msg "Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address"] [data "Matched Data: http://169.254.169.254 found within ARGS:url: http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-rfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/175/253"] [hostname "83.40.216.116"] [uri "/fetch"] [unique_id "apGlubsbzVSQVFQoPYEk3wAAC9M"]
...
show less
Hacking
Web App Attack
🇺🇸
jormaster3k
2026-08-28 07:15:09
(1 week ago)
Attack against Apache (too many 404s)
Web App Attack
🇪🇸
el-brujo
2026-08-28 06:14:28
(1 week ago)
81.27.101.113 - - [28/Aug/2026:08:14:28 +0200] "GET /public/plugins/text/../../../../../../../var/li ...
show more
81.27.101.113 - - [28/Aug/2026:08:14:28 +0200] "GET /public/plugins/text/../../../../../../../var/lib/grafana/grafana.db HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [28/Aug/2026:08:14:28 +0200] "GET /public/plugins/heatmap/../../../../../../../var/lib/grafana/grafana.db HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [28/Aug/2026:08:14:28 +0200] "GET /public/plugins/graph/../../../../../../../etc/grafana/grafana.ini HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [28/Aug/2026:08:14:28 +0200] "GET /public/plugins/table/../../../../../../../var/lib/grafana/grafana.db HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [28/Aug/2026:08:14:28 +0200] "GET /public/plugins/text/../../../../../../../proc/self/environ HTTP/1.1" 400 226 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36"
81.27.101.113 - - [28/Aug/2
...
show less
DDoS Attack
Hacking
🇳🇱
Ilop
2026-08-28 01:34:03
(1 week ago)
[v6-22] Firewall dropped 4 unsolicited packet(s) proto=tcp to port(s) 80,443 from 81.27.101.113 — WA ...
show more
[v6-22] Firewall dropped 4 unsolicited packet(s) proto=tcp to port(s) 80,443 from 81.27.101.113 — WAN scan (automated sensor)
show less
Port Scan
🇵🇱
Budyn
2026-08-27 21:04:08
(1 week ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_6 | Action: AWS API Call | Token: d27d ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_6 | Action: AWS API Call | Token: d27dkqjofz7pprlk36nnrvhej | Client Tool: Boto3/1.43.80 md/Botocore#1.43.80 ua/2.1 os/linux#6.12.94+deb13-cloud-amd64 md/arch#x86_64 lang/python#3.13.5 md/pyimpl#CPython m/b,D,e,Z cfg/retry-mode#lega...
show less
Hacking
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-27 20:41:19
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /api/v1/namespaces/default/secrets | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack