๐ต๐ฑ
Budyn
2026-10-09 16:32:39
(8 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.online | URI: /.env.prod | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 14:22:23
(10 hours ago)
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 68.178.165.65 - - [09/Oct/2026:16:22:06 +0200] "GET /xampp/phpinfo.php HTTP/1.1" 404 7780 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 21:02:43
(1 day ago)
Blocked by ModSec and CSF
Port Scan
๐ฎ๐ฉ
xveil
2026-10-08 19:24:00
(1 day ago)
2026-10-09T02:23:58.261687 mail-honeypot postfix/submission/smtpd[13064]: warning: 65.165.178.68.hos ...
show more
2026-10-09T02:23:58.261687 mail-honeypot postfix/submission/smtpd[13064]: warning: 65.165.178.68.host.secureserver.net[68.178.165.65]: SASL PLAIN authentication failed: authentication failure
...
show less
Brute-Force
๐ฌ๐ท
setupgr
2026-10-08 06:14:45
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 68.178.165.65 (US/United States/-/-/-/[AS2649 ...
show more
(mod_security) mod_security (id:11000011) triggered by 68.178.165.65 (US/United States/-/-/-/[AS26496 GoDaddy.com, LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:14:43.201286 2026] [security2:error] [pid 97464:tid 97528] [remote 68.178.165.65:60622] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "host.secureserver.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 65.165.178.68.host.secureserver.net"] [severity "CRITICAL"] [hostname "tavernadimitris.com"] [uri "/feed/"] [unique_id "asc002UMX1GLeXfHH5h7KgAEGA0"]
show less
Port Scan
๐ฌ๐ท
setupgr
2026-10-08 02:57:25
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 68.178.165.65 (US/United States/-/-/-/[AS2649 ...
show more
(mod_security) mod_security (id:11000011) triggered by 68.178.165.65 (US/United States/-/-/-/[AS26496 GoDaddy.com, LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:57:24.583391 2026] [security2:error] [pid 98043:tid 98107] [remote 68.178.165.65:57008] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "host.secureserver.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 65.165.178.68.host.secureserver.net"] [severity "CRITICAL"] [hostname "setworldup.com"] [uri "/wp-sitemap-users-1.xml"] [unique_id "ascGlN3EWOJwR6hxyyKOeQAExgs"]
show less
Port Scan
๐ธ๐ฎ
administrator
2026-10-07 22:13:46
(2 days ago)
2026-10-07 01:28:00,662 fail2ban.actions [2774549]: NOTICE [webadmin-badips] Ban 68.178.165. ...
show more
2026-10-07 01:28:00,662 fail2ban.actions [2774549]: NOTICE [webadmin-badips] Ban 68.178.165.65
2026-10-07 01:34:12,318 fail2ban.actions [2774549]: NOTICE [webadmin-nfw] Ban 68.178.165.65
2026-10-07 01:28:00,662 fail2ban.actions [2774549]: NOTICE [webadmin-badips] Ban 68.178.165.65
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-07 02:04:43
(2 days ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 68.178.165.65 - - [07/Oct/2026:04:04:38 +0200] "GET /wp-config-sample.php?stringnngyj HTTP/2.0" 500 2482 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.2; WOW64; Trident/7.0)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-07 01:02:24
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฉ๐ช
paissangroup
2026-10-07 00:42:19
(3 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-10-06 23:28:38
(3 days ago)
2026-10-06T23:28:38.087270+00:00 instance-20260804-1025 wordpress(acbp.org.co)[365100]: Immediately ...
show more
2026-10-06T23:28:38.087270+00:00 instance-20260804-1025 wordpress(acbp.org.co)[365100]: Immediately block connections from 68.178.165.65
...
show less
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-10-06 23:21:43
(3 days ago)
68.178.165.65 - - [07/Oct/2026:02:21:42 +0300] "GET /rss/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Window ...
show more
68.178.165.65 - - [07/Oct/2026:02:21:42 +0300] "GET /rss/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
GabrielJST
2026-10-06 21:28:19
(3 days ago)
(smtpauth) Failed SMTP AUTH login from 68.178.165.65 (US/United States/65.165.178.68.host.secureserv ...
show more
(smtpauth) Failed SMTP AUTH login from 68.178.165.65 (US/United States/65.165.178.68.host.secureserver.net)
show less
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-10-06 21:05:08
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐บ๐ธ
rafaelpfister.ch
2026-10-06 20:40:56
(3 days ago)
Blocked by WAF: 1 request(s) probing for PHP scripts, WordPress files or secrets on a site without P ...
show more
Blocked by WAF: 1 request(s) probing for PHP scripts, WordPress files or secrets on a site without PHP: GET /wp-json/wp/v2/users โข Reported by: github.com/pfstr/cloudflare-abuseipdb-reporter
show less
Web App Attack