🇩🇪
Goetz
2026-09-03 09:03:03
(18 hours ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
🇫🇷
Sklurk
2026-09-01 04:49:10
(2 days ago)
Web App Attack
Web App Attack
🇨🇭
backslash
2026-07-11 05:42:05
(1 month ago)
block ruleset 51D5331ECDCF70C2C6410C0D0EEB5F69B17B5F56
Bad Web Bot
🇪🇸
librebit
2026-06-24 11:19:41
(2 months ago)
Brute force
Brute-Force
🇺🇸
TPI-Abuse
2026-06-06 10:49:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 06:49:12.219279 2026] [security2:error] [pid 25913:tid 25913] [client 104.207.39.104:25953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.trafficstopper.com"] [uri "/.env"] [unique_id "aiP7KOCX_Lfk2a0AMuC-ygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Security_Whaller
2026-05-30 01:11:46
(3 months ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack
🇩🇪
big-cloud.nl
2026-02-18 03:47:06
(6 months ago)
Try to access /admin/.git/config
Web App Attack
Anonymous
2026-01-27 16:43:56
(7 months ago)
2026-01-27T18:43:55.568956+02:00 zanati wp(www.sahpa.co.za)[785902]: Blocked authentication attempt ...
show more
2026-01-27T18:43:55.568956+02:00 zanati wp(www.sahpa.co.za)[785902]: Blocked authentication attempt for [email protected] from 104.207.39.104
...
show less
Web App Attack
🇲🇹
Malta
2026-01-01 14:14:23
(8 months ago)
104.207.39.104 - - [01/Jan/2026:15:14:22 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
104.207.39.104 - - [01/Jan/2026:15:14:22 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
show less
VPN IP
Hacking
Web App Attack
🇮🇹
VHosting
2025-12-24 03:10:40
(8 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
🇺🇸
TPI-Abuse
2025-12-08 04:54:00
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 23:53:56.049178 2025] [security2:error] [pid 11186:tid 11186] [client 104.207.39.104:39589] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diarrheawolves.com"] [uri "/.env"] [unique_id "aTZZ5I2FBll9ZntSAmth3gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-07 21:18:52
(8 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 14:58:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 09:58:15.146005 2025] [security2:error] [pid 10227:tid 10237] [client 104.207.39.104:13593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "secdc.org"] [uri "/.git/HEAD"] [unique_id "aTWWBxqBvnTvP15HQmy8DgAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-07 13:45:49
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 08:45:42.164084 2025] [security2:error] [pid 3578:tid 3578] [client 104.207.39.104:47199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimmyshakes.org"] [uri "/.svn/wc.db"] [unique_id "aTWFBlBZNIXe7ZiOrH7yGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-05 11:36:27
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 06:36:22.228922 2025] [security2:error] [pid 30258:tid 30258] [client 104.207.39.104:20973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "turn-keyit.com"] [uri "/.env"] [unique_id "aTLDtlW0qqYFVsYL2xP-WgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack