๐บ๐ธ
drewf.ink
2026-08-29 14:04:33
(3 days ago)
[14:04] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[14:04] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-13 04:24:33
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ซ๐ท
Sklurk
2026-08-01 00:07:01
(1 month ago)
Web App Attack
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-08 11:37:56
(1 month ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐บ๐ธ
TAY
2026-06-14 07:36:05
(2 months ago)
104.207.46.22 - - [14/Jun/2026:15:36:02 +0800] "GET /wp-admin/admin.php?page=miwoftp&option=com_miwo ...
show more
104.207.46.22 - - [14/Jun/2026:15:36:02 +0800] "GET /wp-admin/admin.php?page=miwoftp&option=com_miwoftp&action=download&item=..%2Fwp-config.php&order=name&srt=yes HTTP/1.1" 301 657 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0"
104.207.46.22 - - [14/Jun/2026:15:36:03 +0800] "GET /wp-admin/admin.php?page=newsletters-history&wpmlmethod=exportdownload&file=..%2Fwp-config.php HTTP/1.1" 301 613 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0"
104.207.46.22 - - [14/Jun/2026:15:36:04 +0800] "GET /wp-admin/edit.php?page=wp-db-backup.php&backup=..%2Fwp-config.php HTTP/1.1" 301 553 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0"
...
show less
Brute-Force
๐ฌ๐ง
PeravixGroup
2026-06-09 15:51:08
(2 months ago)
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity ...
show more
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐จ๐ญ
4server
2026-05-11 09:16:53
(3 months ago)
[MonMay1111:16:48.6357082026][security2:error][pid4097884:tid4097911][client104.207.46.22:0]ModSecur ...
show more
[MonMay1111:16:48.6357082026][security2:error][pid4097884:tid4097911][client104.207.46.22:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"pmprogettazione.ch\"][uri\"/.env\"][unique_id\"agGegDw-8q3Z2RyAjLy-NwAAAQ4\"]
show less
Hacking
Web App Attack
๐บ๐ธ
octageeks.com
2026-04-15 04:07:00
(4 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐บ๐ธ
mnsf
2026-02-16 02:06:16
(6 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 11:57:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:57:16.683508 2026] [security2:error] [pid 12789:tid 12795] [client 104.207.46.22:45541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teanaunz.com"] [uri "/site/.git/config"] [unique_id "aZG0nB0_RFMVRLILfS0sPwAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-15 11:52:12
(6 months ago)
Blocking for trying to access an exploit file: /frontend/.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-15 05:26:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:25:56.152158 2026] [security2:error] [pid 21311:tid 21311] [client 104.207.46.22:30835] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supportourlibrary.org"] [uri "/dev/.git/config"] [unique_id "aZFY5O0c7a2jaKvI_RwHIAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-15 04:48:28
(6 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /wp/.git/config (Rule ID: 930130) - Restricted File Access Attempt
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:29:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:29:35.245176 2026] [security2:error] [pid 2458653:tid 2458653] [client 104.207.46.22:46043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stsis.me"] [uri "/dev/.git/config"] [unique_id "aZFLr-PanvcAVkcKU-SczAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:37:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:37:46.177656 2026] [security2:error] [pid 9372:tid 9372] [client 104.207.46.22:14827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stefchild.com"] [uri "/dev/.git/config"] [unique_id "aZE_iuvLPcO_if8SPBOl2QAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack