๐บ๐ธ
Ben Schoolland
2026-09-17 12:57:33
(15 hours ago)
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legiti ...
show more
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legitimate use.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 02:58:23
(1 week ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ธ๐ช
OnTheEdge
2026-09-04 09:08:33
(1 week ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ฉ๐ช
NxtGenIT
2026-09-03 16:58:01
(2 weeks ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html HTTP/1.1" 302 -,
Brute-Force
๐จ๐ฟ
lp
2026-09-03 01:49:25
(2 weeks ago)
Unauthorized VPN login attempts: 7 attempts were recorded from 104.167.19.128
2026-09-03T03:30:39+02 ...
show more
Unauthorized VPN login attempts: 7 attempts were recorded from 104.167.19.128
2026-09-03T03:30:39+02:00 vpn Access-Reject 'q' station: 104.167.19.128 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T03:32:12+02:00 vpn Access-Reject 'reuniao' station: 104.167.19.128 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T03:33:41+02:00 vpn Access-Reject 'charles' station: 104.167.19.128 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T03:35:17+02:00 vpn Access-Reject 'marketing' station: 104.167.19.128 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T03:36:53+02:00 vpn Access-Reject 'helpdesk' station: 104.167.19.128 auth-type: - realm: vse.cz nas: <r
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Goetz
2026-09-02 14:56:39
(2 weeks ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
๐ธ๐ช
OnTheEdge
2026-09-02 10:59:22
(2 weeks ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-31 04:06:55
(2 weeks ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-03-15 06:46:30
(6 months ago)
Brute force
Brute-Force
Anonymous
2026-01-16 14:35:33
(8 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 12:57:03
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.167.19.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.167.19.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 07:56:57.070950 2026] [security2:error] [pid 10181:tid 10181] [client 104.167.19.128:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avaliantlife.com"] [uri "/.env"] [unique_id "aV5YGQXpHAHl4keqMtjphgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 06:00:27
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.167.19.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.167.19.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:00:22.368451 2025] [security2:error] [pid 17121:tid 17140] [client 104.167.19.128:26419] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "g3-contracting.com"] [uri "/.svn/wc.db"] [unique_id "aVIY9rW73w_xDGZnXivN-wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:33:36
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.167.19.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.167.19.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:33:33.874447 2025] [security2:error] [pid 29518:tid 29518] [client 104.167.19.128:44937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "targetbinario.com"] [uri "/.env"] [unique_id "aVISrZtOc5SkRE5Gqr2PbgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:08:47
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.167.19.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.167.19.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:08:43.393109 2025] [security2:error] [pid 11731:tid 11731] [client 104.167.19.128:44459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atcreport.com"] [uri "/.git/HEAD"] [unique_id "aVH-y0eJj82zm-WsxTMydQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-08 11:25:55
(9 months ago)
botnet
DDoS Attack