Anonymous
2026-05-31 10:24:19
(1 week ago)
[ssd5.kdns.gr] httpd-login-spray-site: sites=hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; s ...
show more
[ssd5.kdns.gr] httpd-login-spray-site: sites=hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; samples=site_wide=true | distinct_ips=18 | /wp-login.php
show less
Hacking
Web App Attack
๐ซ๐ท
ELYAZ
2026-05-30 12:17:57
(1 week ago)
(y4) Failed scan -byebye- from 104.207.48.66 (BR/Brazil/-): (CF_ENABLE)
Hacking
๐ซ๐ท
tilellit.pro
2026-05-30 03:38:11
(1 week ago)
Fail2Ban banned 104.207.48.66 for security violations in jail wp-armour. Log: 2026/05/30 03:38:10 [e ...
show more
Fail2Ban banned 104.207.48.66 for security violations in jail wp-armour. Log: 2026/05/30 03:38:10 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 104.207.48.66 | Target: wplogin" , client: 104.207.48.66, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
lostswordfish.com
2026-05-27 13:34:05
(1 week ago)
Wordfence waf block on registrymatters
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-05-24 04:09:56
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฒ๐น
Malta
2026-05-23 15:29:24
(2 weeks ago)
104.207.48.66 - - [23/May/2026:17:29:24 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh ...
show more
104.207.48.66 - - [23/May/2026:17:29:24 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
VPN IP
๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(3 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2025-12-27 13:45:08
(5 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐ธ๐ฌ
anotherwatcher
2025-12-08 20:25:52
(5 months ago)
bad bot
Bad Web Bot
๐ซ๐ท
mrcrassi
2025-12-08 02:13:26
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-06 19:51:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 14:51:18.195871 2025] [security2:error] [pid 29547:tid 29547] [client 104.207.48.66:19091] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "belgiophar.net"] [uri "/.env"] [unique_id "aTSJNrkR_0SDae9cIXeWwgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 11:42:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 06:42:38.184294 2025] [security2:error] [pid 24730:tid 24730] [client 104.207.48.66:51377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asaint.net"] [uri "/.svn/wc.db"] [unique_id "aTQWrlGris0k5aXBFXxTiAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 05:20:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 00:20:30.388278 2025] [security2:error] [pid 2064:tid 2064] [client 104.207.48.66:51559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fingerprintinternational.com"] [uri "/.env"] [unique_id "aTJrnkg5SJERqO-nkMRMKwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-27 15:50:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 10:50:21.457870 2025] [security2:error] [pid 27284:tid 27284] [client 104.207.48.66:35329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dodgersboosterclub.com"] [uri "/.git/HEAD"] [unique_id "aShzPYX-dRj_AwiRi1gU7wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:15:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.48.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:14:55.242393 2025] [security2:error] [pid 1472:tid 1472] [client 104.207.48.66:60227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.superlambauto.superlamb.com"] [uri "/.git/HEAD"] [unique_id "aSVXb8i97ckmpHerhwSq-AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack