๐ฌ๐ท
setupgr
2026-07-30 01:07:36
(1 day ago)
(wplogin_block) Blocked WP-Login Access Attempt 104.207.33.87 (US/United States/Virginia/Ashburn/-/[ ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 104.207.33.87 (US/United States/Virginia/Ashburn/-/[AS200373 DREI-K-TECH-GMBH]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.207.33.87 - - [30/Jul/2026:04:06:24 +0300] "POST /wp-login.php HTTP/1.1" 301 286 "https://doityourself.gr/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15"
show less
Port Scan
Anonymous
2026-07-28 06:06:28
(2 days ago)
Trying to access config files
Web App Attack
๐จ๐ญ
4server
2026-07-06 11:00:49
(3 weeks ago)
[MonJul0613:00:43.9075402026][security2:error][pid3162488:tid3162643][client104.207.33.87:0]ModSecur ...
show more
[MonJul0613:00:43.9075402026][security2:error][pid3162488:tid3162643][client104.207.33.87:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"vetreriaperletti.ch\"][uri\"/wp-login.php\"][unique_id\"akuK24f2QV6k4kUVJf8ZWQAAAEk\"]\,referer:https://vetreriaperletti.ch/wp-login.php
show less
Hacking
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-06 04:12:45
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ซ๐ท
ELYAZ
2026-07-04 08:34:39
(3 weeks ago)
(y4) Failed scan -byebye- from 104.207.33.87 (US/United States/-): (CF_ENABLE)
Hacking
Anonymous
2026-07-03 23:15:57
(3 weeks ago)
Web attack blocked by Wordfence on limburgsekunstkring.nl (1 hit). Reported by CRMON.
Web App Attack
๐ซ๐ท
ELYAZ
2026-07-03 01:43:03
(4 weeks ago)
(y4) Failed scan -byebye- from 104.207.33.87 (US/United States/-): (CF_ENABLE)
Hacking
๐บ๐ธ
lostswordfish.com
2026-07-02 13:24:03
(4 weeks ago)
Wordfence waf block on taussigtravel
Web App Attack
๐ฉ๐ช
LRob
2026-06-23 18:15:20
(1 month ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-05-06 17:53:45
(2 months ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-02-19 03:59:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:59:01.796188 2026] [security2:error] [pid 6210:tid 6210] [client 104.207.33.87:9541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirbysmw.com"] [uri "/admin/.env"] [unique_id "aZaKhUE7MKyUpCUOTXE3ggAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:10:17
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:10:10.563496 2026] [security2:error] [pid 28457:tid 28457] [client 104.207.33.87:57349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katherinehowell.us"] [uri "/.env"] [unique_id "aZZxApRYzF0QDI3afsJ1jAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 18:27:45
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:27:40.863639 2026] [security2:error] [pid 24841:tid 24841] [client 104.207.33.87:18037] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thetribehouse.com"] [uri "/api/.git/config"] [unique_id "aZYEnJzlS7qMx-fhs1SnnwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-18 15:06:03
(5 months ago)
Scanning/Probing (22)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:20:09
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.33.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.33.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:20:04.375088 2026] [security2:error] [pid 18046:tid 18046] [client 104.207.33.87:57559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weat.net"] [uri "/.env.production"] [unique_id "aZWudP5SXZUl4_nw90QZYgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack