Anonymous
2026-09-05 14:27:43
(10 hours ago)
Kritik Bal Küpü (Honeypot) Tuzağı Tetiklendi (/wp-login.php). Subnet karantinaya alındı.
Hacking
Web App Attack
🇸🇪
OnTheEdge
2026-09-04 08:42:52
(1 day ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇺🇸
ambor
2026-09-02 02:27:41
(3 days ago)
Honeypot access: WordPress XML-RPC attack attempt. Path: /xmlrpc.php
Brute-Force
Web App Attack
🇬🇧
spamverify.com
2026-09-01 19:31:24
(4 days ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
🇫🇷
Sklurk
2026-07-29 01:18:19
(1 month ago)
Web App Attack
Web App Attack
Anonymous
2026-07-18 05:58:39
(1 month ago)
2026/07/18 02:58:31 [error] 1461#1461: *2328 openat() "/var/www/temcomercio.com.br/web/public/wp-inc ...
show more
2026/07/18 02:58:31 [error] 1461#1461: *2328 openat() "/var/www/temcomercio.com.br/web/public/wp-includes/wlwmanifest.xml" failed (2: No such file or directory), client: 104.207.48.26, server: temcomercio.com.br, request: "GET //wp-includes/wlwmanifest.xml HTTP/1.1", host: "www.temcomercio.com.br"
2026/07/18 02:58:31 [error] 1461#1461: *2328 openat() "/var/www/temcomercio.com.br/web/public/blog/wp-includes/wlwmanifest.xml" failed (2: No such file or directory), client: 104.207.48.26, server: temcomercio.com.br, request: "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1", host: "www.temcomercio.com.br"
2026/07/18 02:58:32 [error] 1461#1461: *2328 openat() "/var/www/temcomercio.com.br/web/public/web/wp-includes/wlwmanifest.xml" failed (2: No such file or directory), client: 104.207.48.26, server: temcomercio.com.br, request: "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1", host: "www.temcomercio.com.br"
...
show less
Port Scan
🇲🇽
octageeks.com
2026-06-24 04:15:10
(2 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇦🇱
cheatmaster.store
2026-02-27 02:10:51
(6 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: Canada
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
🇳🇱
homeshowdomain.nl
2026-02-09 22:59:02
(6 months ago)
Auto-ban: >3000 req/min op 2026-02-09
Hacking
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-02-09 21:48:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:48:23.370834 2026] [security2:error] [pid 11282:tid 11282] [client 104.207.48.26:28871] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garyrankin.com"] [uri "/frontend/.env"] [unique_id "aYpWJxNT0IFFL67vdM2sWwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 20:40:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:39:57.261632 2026] [security2:error] [pid 32233:tid 32233] [client 104.207.48.26:45467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gamepart.com"] [uri "/config/.env"] [unique_id "aYpGHRJJZyhJoKkyfq-aJgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 19:37:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 14:37:03.929657 2026] [security2:error] [pid 20720:tid 20720] [client 104.207.48.26:21355] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gabver.com"] [uri "/.env"] [unique_id "aYo3XyWlTQSpWgUBKlRXSgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 16:32:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 11:32:20.919893 2026] [security2:error] [pid 4466:tid 4466] [client 104.207.48.26:48671] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftwwx.com"] [uri "/wp/.git/config"] [unique_id "aYoMFJ9HLQEQvtFtggfc9QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 12:44:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 07:44:49.451687 2026] [security2:error] [pid 30817:tid 30817] [client 104.207.48.26:35219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gamerah.net"] [uri "/api/.git/config"] [unique_id "aYnWwdL5JqE3t-nHQY90bwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
barbarella
2026-02-09 10:07:18
(6 months ago)
hacking attempt of version control system (GET /app/.git/config)
Hacking
Web App Attack