Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=17; exact paths: /xmlrpc.php
Web App Attack
🇬🇧
gigatech
2026-07-23 21:05:11
(1 month ago)
Webserver Probing
Web App Attack
Anonymous
2026-07-23 06:42:07
(1 month ago)
WordPress Brute Force
Brute-Force
🇩🇪
stinpriza
2026-07-12 04:51:25
(1 month ago)
Web App Attack
Web App Attack
🇲🇹
Malta
2026-05-31 06:15:54
(3 months ago)
104.207.47.160 - - [31/May/2026:08:15:54 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Ubu ...
show more
104.207.47.160 - - [31/May/2026:08:15:54 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇦
URAN Publishing Service
2026-05-31 04:35:52
(3 months ago)
104.207.47.160 - - [31/May/2026:07:35:23 +0300] "POST /wp-login.php HTTP/1.1" 404 3297 "https://nrpl ...
show more
104.207.47.160 - - [31/May/2026:07:35:23 +0300] "POST /wp-login.php HTTP/1.1" 404 3297 "https://nrpling.ukma.edu.ua/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
104.207.47.160 - - [31/May/2026:07:35:51 +0300] "POST /wp-login.php HTTP/1.1" 404 3297 "https://nrpling.ukma.edu.ua/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-05-30 19:26:03
(3 months ago)
[ssd5.kdns.gr] httpd-login-spray-site: sites=e-anastasiadis.gr; logs=/var/log/httpd/domains/e-anasta ...
show more
[ssd5.kdns.gr] httpd-login-spray-site: sites=e-anastasiadis.gr; logs=/var/log/httpd/domains/e-anastasiadis.gr.log; samples=site_wide=true | distinct_ips=48 | /wp-login.php
show less
Hacking
Web App Attack
🇫🇷
Tilellit.PRO
2026-05-30 03:34:51
(3 months ago)
Fail2Ban banned 104.207.47.160 for security violations in jail wp-armour. Log: 2026/05/30 03:34:51 [ ...
show more
Fail2Ban banned 104.207.47.160 for security violations in jail wp-armour. Log: 2026/05/30 03:34:51 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 104.207.47.160 | Target: wplogin" , client: 104.207.47.160, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
Anonymous
2026-03-13 22:06:45
(5 months ago)
Forum/form spam
Web Spam
🇺🇸
TPI-Abuse
2026-02-19 03:56:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.47.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.47.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:56:48.393305 2026] [security2:error] [pid 30582:tid 30582] [client 104.207.47.160:28417] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinnerakhareedu.com"] [uri "/new/.git/config"] [unique_id "aZaKAOmv-pyfIbkk2SchWAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-19 03:04:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.47.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.47.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:04:46.328773 2026] [security2:error] [pid 21107:tid 21107] [client 104.207.47.160:14407] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentsavagelaw.com"] [uri "/.env.local"] [unique_id "aZZ9zp_bj9r07eGLYNWyTAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-02-19 01:39:02
(6 months ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-02-19 01:29:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.47.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.47.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 20:29:23.160860 2026] [security2:error] [pid 14119:tid 14142] [client 104.207.47.160:55613] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kandooo.com"] [uri "/frontend/.env"] [unique_id "aZZnc87LbDS5IjHn1_w9zwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-02-18 22:59:16
(6 months ago)
Auto-ban: >3000 req/min op 2026-02-18
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-02-18 13:15:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.47.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.47.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:15:51.152352 2026] [security2:error] [pid 22352:tid 22352] [client 104.207.47.160:28119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildcomaui.com"] [uri "/.env.production"] [unique_id "aZW7h6K0yIAnCgIe_xkeTQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack