🇩🇪
ghostwarriors
2026-09-21 02:50:08
(8 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-21 02:44:51
(8 hours ago)
104.207.45.93 - - [21/Sep/2026:04:44:18 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 4521 "-" " ...
show more
104.207.45.93 - - [21/Sep/2026:04:44:18 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 4521 "-" "CMS-Security-Auditor/1.0 (+authorized self-check; contact: local-admin)"
104.207.45.93 - - [21/Sep/2026:04:44:22 +0200] "GET /wp-json/ HTTP/1.1" 200 201033 "-" "CMS-Security-Auditor/1.0 (+authorized self-check; contact: local-admin)"
104.207.45.93 - - [21/Sep/2026:04:44:26 +0200] "GET /?rest_route=/ HTTP/1.1" 200 201033 "-" "CMS-Security-Auditor/1.0 (+authorized self-check; contact: local-admin)"
104.207.45.93 - - [21/Sep/2026:04:44:31 +0200] "GET /wp-content/plugins/wp-ticket/readme.txt HTTP/1.1" 404 30691 "-" "CMS-Security-Auditor/1.0 (+authorized self-check; contact: local-admin)"
104.207.45.93 - - [21/Sep/2026:04:44:35 +0200] "GET /wp-content/plugins/wp-automatic/readme.txt HTTP/1.1" 404 30691 "-" "CMS-Security-Auditor/1.0 (+authorized self-check; contact: local-admin)"
104.207.45.93 - - [21/Sep/2026:04:44:39 +0200] "GET /wp-content/plugins/wp-fastest-cache/readme.txt HTTP/1.1" 404 3
show less
Web App Attack
Hacking
🇫🇷
Sklurk
2026-08-08 02:51:20
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-08 01:36:49
(2 months ago)
Web App Attack
Web App Attack
🇦🇺
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
🇱🇻
garmtech.com
2026-03-15 18:48:00
(6 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
Anonymous
2026-02-24 03:34:49
(6 months ago)
Probing to gain illegal access
Web App Attack
🇺🇸
TPI-Abuse
2026-02-23 14:36:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 09:36:30.401339 2026] [security2:error] [pid 3329:tid 3353] [client 104.207.45.93:30723] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fandginsurancellc.antidote-it.com"] [uri "/.git/config"] [unique_id "aZxl7olCXX14Kq66x8s3BQAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-23 12:24:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 07:24:45.217240 2026] [security2:error] [pid 18331:tid 18344] [client 104.207.45.93:46893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafmgcc.com.aafm.us"] [uri "/.git/config"] [unique_id "aZxHDf4jBgY6Tvod8buwkwAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
fbarela
2026-01-25 03:00:15
(7 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-12-22 16:46:15
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
🇺🇸
nowyouknow
2025-12-12 11:09:26
(9 months ago)
Phishing
Web Spam
🇺🇸
nowyouknow
2025-11-25 12:31:04
(9 months ago)
Phishing
Web Spam
🇺🇸
TPI-Abuse
2025-11-24 08:03:37
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:03:32.889908 2025] [security2:error] [pid 16742:tid 16742] [client 104.207.45.93:52909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.glaswoodind.com"] [uri "/.git/HEAD"] [unique_id "aSQRVMw7mohSMrwHJQTAIwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:24:31
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:24:23.417142 2025] [security2:error] [pid 9149:tid 9149] [client 104.207.45.93:25183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.patrickconklin.com"] [uri "/.svn/wc.db"] [unique_id "aSQIJ0c9v8ujFyMkfnPNkQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack