🇭🇺
bcsaba
2026-08-30 18:50:18
(9 hours ago)
CMS (WordPress or Joomla) login attempt.
104.207.38.154 - - [30/Aug/2026:20:50:16 +0200] "POST /wp-l ...
show more
CMS (WordPress or Joomla) login attempt.
104.207.38.154 - - [30/Aug/2026:20:50:16 +0200] "POST /wp-login.php HTTP/1.1" 200 3503 "https://*REDACTED*/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15"
show less
Hacking
Brute-Force
Web App Attack
🇷🇴
iulianh
2026-08-29 11:16:40
(1 day ago)
80,443
Brute-Force
SSH
🇹🇷
oalver
2026-08-28 23:29:40
(2 days ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /xmlrpc.php (HTTP 200). First seen: 2026-08-28. Risk score: 30/100.
show less
Web App Attack
🇫🇷
Sklurk
2026-07-16 00:23:49
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-06-23 03:51:47
(2 months ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-06-20 02:37:54
(2 months ago)
Web App Attack
Web App Attack
🇺🇸
technojoe99
2026-06-13 11:56:26
(2 months ago)
Exploit scan from 104.207.38.154. GET http://usprivatecloud.net/sitemap.xml HTTP/1.1.
Web App Attack
🇨🇦
ISPLtd
2026-02-27 01:32:56
(6 months ago)
Hacking, URL manipulation, malformed requests, or requests for invalid/hidden files like .git/config ...
show more
Hacking, URL manipulation, malformed requests, or requests for invalid/hidden files like .git/config or .env. Varying user agents. Does not honour robots.txt.
show less
Hacking
Web App Attack
Bad Web Bot
🇺🇸
OceanTreasure
2026-02-13 13:15:27
(6 months ago)
tcp/443; Git configuration exposure attempt: "GET /site/.git/config" @ 2026-02-13T13:12:57Z [proxy]
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 13:12:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 08:12:34.393181 2026] [security2:error] [pid 31420:tid 31420] [client 104.207.38.154:51733] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lavozdominicana.com"] [uri "/.env.staging"] [unique_id "aY8jQu8CHHQieGLw-zvoQQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
masterguru
2026-02-13 13:04:56
(6 months ago)
. Matched phrase "/.env" at REQUEST_URI. (210492-123)
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 07:04:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 02:03:59.222218 2026] [security2:error] [pid 3502:tid 3502] [client 104.207.38.154:29637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medics-group.com"] [uri "/test/.git/config"] [unique_id "aY7M35a8g6WSOZ4QK5-rTgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 06:07:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 01:06:56.120739 2026] [security2:error] [pid 5521:tid 5521] [client 104.207.38.154:20069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mccachren.org"] [uri "/config/.env"] [unique_id "aY6_gEhGx8JqPTcwxqw2ggAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 04:30:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 23:30:48.843337 2026] [security2:error] [pid 24962:tid 24962] [client 104.207.38.154:60947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marveldirectory.com"] [uri "/app/.git/config"] [unique_id "aY6o-DI3-ax9sVSFVm5jGAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-02-13 03:06:20
(6 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack