๐บ๐ธ
ctrlpew
2026-05-19 01:01:02
(3 weeks ago)
WordPress login brute-force botnet targeting ctrlpew.com. Distributed IPs cycling every 3 seconds wi ...
show more
WordPress login brute-force botnet targeting ctrlpew.com. Distributed IPs cycling every 3 seconds with UA rotation. All attempts against non-existent usernames. 2026-05-18.
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-01-24 17:43:15
(4 months ago)
[WAZUH] Mixed Case Gambling Pattern Detection
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-21 15:03:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 10:03:06.398971 2026] [security2:error] [pid 30997:tid 30997] [client 104.207.46.91:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perl-photo.com"] [uri "/.git/HEAD"] [unique_id "aXDqqpZpND_sqkhetQ5fyAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-20 21:44:55
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐ฆ๐บ
afleventoffice.com.au
2026-01-20 14:21:17
(4 months ago)
GET /.git/HEAD HTTP/1.1
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-01-20 06:40:50
(4 months ago)
GET /.svn/wc.db HTTP/1.1
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-13 06:46:39
(5 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฎ๐น
VHosting
2025-12-23 15:20:26
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-12-02 19:08:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 14:08:18.024934 2025] [security2:error] [pid 21146:tid 21146] [client 104.207.46.91:38139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onlinesoldier.com"] [uri "/.env"] [unique_id "aS85IklTeWrtmHL2XMk3tgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 07:45:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:45:34.563704 2025] [security2:error] [pid 19965:tid 19965] [client 104.207.46.91:40777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "the-it-man.com"] [uri "/.env"] [unique_id "aS6ZHtc4oR7M273NFZJg4gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:34:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.46.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.46.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:34:50.178474 2025] [security2:error] [pid 15568:tid 15568] [client 104.207.46.91:34083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "villandance.com"] [uri "/.env"] [unique_id "aS56etnWu5SDgm0EP7QQawAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-27 01:20:55
(7 months ago)
(sshd) Failed SSH login from 104.207.46.91 (US/United States/-)
Brute-Force
SSH
๐บ๐ธ
kosada.com
2025-10-25 01:06:04
(7 months ago)
Web password guessing
Brute-Force
๐จ๐ฆ
wil.com
2025-10-18 03:27:44
(7 months ago)
GlobalProtect login attempts with user donaldmiller.
VPN IP
Brute-Force
๐ง๐ท
hostseries
2025-10-12 18:17:56
(8 months ago)
Trigger: LF_DISTATTACK
Brute-Force