🇳🇱
homeshowdomain.nl
2026-08-15 21:59:32
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-14.
show less
Web App Attack
SSH
Hacking
🇵🇱
Budyn
2026-08-15 09:39:14
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sweetpuddingtrap.online | URI: /.env | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Mobile/15E148 Safari/604. | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇵🇱
Budyn
2026-08-15 04:21:56
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: docker.definitelynotahoneypot.top | URI: /home/.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36 Edg/134.0.3124.85 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇫🇷
dynamix
2026-08-15 01:11:37
(3 weeks ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-14 01:33:05
(3 weeks ago)
Aggressive web scan
Web App Attack
🇵🇱
Budyn
2026-08-13 10:57:35
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cloud.teddypot.site | URI: /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36 OPR/118.0.0.0 | BODY: <?php echo(md5("Hello"));
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-13 00:48:07
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.xyz | URI: /lib/phpunit/phpunit/Util/PHP/eval-stdin.php | UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Mobile Safari/537.3 | BODY: <?php echo(md5("Hello"));
show less
Hacking
Web App Attack
🇮🇹
VHosting
2026-08-12 11:35:03
(3 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-08-12 06:40:39
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.tech | URI: /public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1.1 Mobile/15E148 Safari/604. | BODY: <?php echo(md5("Hello"));
show less
Hacking
Web App Attack
🇩🇪
big-cloud.nl
2026-08-12 00:45:57
(3 weeks ago)
Try to access /backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
Web App Attack
🇵🇱
Budyn
2026-08-11 18:08:16
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jira.teddypot.space | URI: /admin/.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇩🇪
ghostwarriors
2026-05-31 09:51:30
(3 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-05-22 17:50:59
(3 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-18 22:54:08
(3 months ago)
(caddyscan) Scanner path probe from 194.126.177.19 (DE/Germany/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 194.126.177.19 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:22:54:05 +0000] "GET /.env.email HTTP/1.1"
[REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:22:54:05 +0000] "GET /.env.email HTTP/1.1"
[REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:22:54:06 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:22:54:07 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:22:54:07 +0000] "GET /.env-speed HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-18 21:54:55
(3 months ago)
(caddyscan) Scanner path probe from 194.126.177.19 (DE/Germany/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 194.126.177.19 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:21:54:52 +0000] "GET /wp-admin/maint/wp-is.php HTTP/1.1"
[REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:21:54:53 +0000] "GET /.env.example HTTP/1.1"
[REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:21:54:54 +0000] "GET /.env.example HTTP/1.1"
[REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:21:54:54 +0000] "GET /lab/.env HTTP/1.1"
[REDACTED] 200 2627 194.126.177.19 - - [18/May/2026:21:54:55 +0000] "GET /lab/.env HTTP/1.1"
show less
Port Scan