๐ท๐บ
Mga Admin
2026-09-01 22:20:12
(10 hours ago)
[Wed Sep 02 05:20:11.596930 2026] [authz_core:error] [pid 2970424:tid 2970540] [client 123.6.49.16:1 ...
show more
[Wed Sep 02 05:20:11.596930 2026] [authz_core:error] [pid 2970424:tid 2970540] [client 123.6.49.16:18913] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
cwytech
2026-09-01 12:57:45
(19 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
nodepile
2026-08-31 21:52:34
(1 day ago)
Requests denied due to active blacklist hits (tenant=82 method=GET path=/ ua='Mozilla/5.0 (Linux; An ...
show more
Requests denied due to active blacklist hits (tenant=82 method=GET path=/ ua='Mozilla/5.0 (Linux; Android 11; CPH2185) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Mobile Safari/537.36')
show less
Web App Attack
Exploited Host
๐จ๐ฟ
ddw
2026-08-30 13:55:36
(2 days ago)
Access Violation Attempts - Multiple 403 Forbidden responses.
Hacking
Bad Web Bot
Web App Attack
๐ฆ๐บ
Bay13
2026-08-30 05:07:25
(3 days ago)
CrowdSec:custom/http-probing
Web App Attack
๐ต๐ฑ
Budyn
2026-08-29 18:57:50
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jira.sweetpuddingtrap.online | URI: /backup.sql | UA: Mozilla/5.0 (Linux; Android 11; V2055A) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-29 11:54:18
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: www.dont-eat-the-pudding.xyz | URI: /backup.sql | UA: Mozilla/5.0 (Linux; Android 10; HUAWEI P30 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.105 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฌ๐ท
setupgr
2026-08-29 04:58:37
(4 days ago)
(mod_security) mod_security (id:100011) triggered by 123.6.49.16 (CN/China/Henan/Zhengzhou/-/[AS4837 ...
show more
(mod_security) mod_security (id:100011) triggered by 123.6.49.16 (CN/China/Henan/Zhengzhou/-/[AS4837 CHINA169-BACKBONE CHINA UNICOM China169 Backbone]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:58:32.597279 2026] [security2:error] [pid 156892:tid 156944] [client 123.6.49.16:56391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CN" at GEO:COUNTRY_CODE. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "62"] [id "100011"] [msg "Traffic from CN/SG blocked for ftiaxtomonosou.gr"] [hostname "ftiaxtomonosou.gr"] [uri "/"] [unique_id "apJm-Cnzwn9qihpQGgO4jQAAAAo"]
show less
Port Scan
๐บ๐ธ
cwytech
2026-08-28 07:24:34
(5 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-22 10:10:33
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cdn.definitelynotahoneypot.top | URI: /.env | UA: Mozilla/5.0 (Linux; Android 10; HUAWEI P30 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.105 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
klaus_ph
2026-08-20 04:07:59
(1 week ago)
123.6.49.16 - - [19/Aug/2026:02:52:56 +0200] "GET /favicon.ico HTTP/1.1" 404 448 "-" "Mozilla/5.0 (W ...
show more
123.6.49.16 - - [19/Aug/2026:02:52:56 +0200] "GET /favicon.ico HTTP/1.1" 404 448 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.3904.108 Safari/537.36"
...
show less
Bad Web Bot
๐ฆ๐บ
FireGuard Server
2026-08-18 02:45:19
(2 weeks ago)
Blocked by os-abuseipdb; 3 hits, proto=tcp, ports=443
Port Scan
Hacking
๐ฎ๐ช
Coolnagour
2026-08-18 02:10:32
(2 weeks ago)
bot entered honeypot
Web App Attack
๐จ๐ณ
primal
2026-08-15 15:24:01
(2 weeks ago)
Automated attack traffic against a WordPress site: automated bot traffic, failed JavaScript challeng ...
show more
Automated attack traffic against a WordPress site: automated bot traffic, failed JavaScript challenge at CDN edge (1x). Blocked by CDN/WAF/application security layers. Total 1 hits in last 30 days.
show less
Bad Web Bot
๐บ๐ธ
ambor
2026-08-14 10:58:54
(2 weeks ago)
Honeypot access: Web shell access attempt. Path: /cmd.php
Hacking
Web App Attack