๐ง๐ช
voormedia
2026-09-02 01:01:09
(2 hours ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐ฉ๐ช
4server
2026-09-01 01:48:09
(1 day ago)
[TueSep0103:48:06.2867172026][security2:error][pid3495661:tid3495723][client104.207.33.79:0]ModSecur ...
show more
[TueSep0103:48:06.2867172026][security2:error][pid3495661:tid3495723][client104.207.33.79:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"cst-ranghetti.ch\"][uri\"/xmlrpc.php\"][unique_id\"apYu1uEjdhwhR050-ISImQAAAIE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฆ๐บ
electronico
2026-08-31 22:02:01
(1 day ago)
104.207.33.79 - - [01/Sep/2026:09:02:01 +1100] "GET /xmlrpc.php HTTP/1.1" 404 6064 "-" "Mozilla/5.0 ...
show more
104.207.33.79 - - [01/Sep/2026:09:02:01 +1100] "GET /xmlrpc.php HTTP/1.1" 404 6064 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-08-31 20:46:34
(1 day ago)
2026-08-31T20:46:33.475277+00:00 instance-20260804-1025 wordpress(netal.co)[1132350]: XML-RPC authen ...
show more
2026-08-31T20:46:33.475277+00:00 instance-20260804-1025 wordpress(netal.co)[1132350]: XML-RPC authentication attempt for unknown user ngadimin from 104.207.33.79
...
show less
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-08-31 13:10:04
(1 day ago)
Wordfence waf block on pameganslaw
Web App Attack
๐ฉ๐ช
0x44
2026-08-30 19:03:44
(2 days ago)
Abusive host detected - WordPress vulnerability scanning
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-08-29 09:55:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
Sklurk
2026-08-09 02:48:01
(3 weeks ago)
Web App Attack
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 05:49:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:49:30.666520 2026] [security2:error] [pid 29400:tid 29400] [client 104.207.33.79:33475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koeckeritz.com"] [uri "/frontend/.env"] [unique_id "aYrG6u0bJ5PZQ6556ypvbgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 04:10:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:09:53.262004 2026] [security2:error] [pid 28362:tid 28362] [client 104.207.33.79:58907] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icesoft.blog"] [uri "/.env.save"] [unique_id "aYqvkTY-Kwq73-CZRdERUQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:43:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:43:49.853461 2026] [security2:error] [pid 18550:tid 18550] [client 104.207.33.79:27509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magazinesubscriptionsusa.com"] [uri "/app/.env"] [unique_id "aYqpdQAC945Qu_wQnE-t9gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:50:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:50:18.739928 2026] [security2:error] [pid 1398003:tid 1398003] [client 104.207.33.79:9293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madisonworkshopwest.com"] [uri "/.git/config"] [unique_id "aYqc6nDcQNtEoays4zh5aAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:42:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:42:45.086395 2026] [security2:error] [pid 14178:tid 14178] [client 104.207.33.79:30449] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kelvinlouie.com"] [uri "/.env.staging"] [unique_id "aYpw9XB0p0NkMtAyyg-dHwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-30 13:09:59
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam