Anonymous
2026-06-21 21:27:55
(1 day ago)
[ns3.backorder.gr] httpd-login-spray-site: sites=debug-gosolar.gr; logs=/var/log/httpd/domains/debug ...
show more
[ns3.backorder.gr] httpd-login-spray-site: sites=debug-gosolar.gr; logs=/var/log/httpd/domains/debug-gosolar.gr.log; samples=site_wide=true | distinct_ips=46 | /wp-login.php
show less
Hacking
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-17 02:17:29
(5 days ago)
(y4) Failed scan -byebye- from 104.207.49.156 (BR/Brazil/-): (CF_ENABLE)
Hacking
๐ฌ๐ง
poundawebsiteltd
2026-06-15 23:20:11
(1 week ago)
WP Exploit attempt. Evidence: [REDACTED_DOMAIN]:443 104.207.49.156 - - [16/Jun/2026:00:20:02 +0100] ...
show more
WP Exploit attempt. Evidence: [REDACTED_DOMAIN]:443 104.207.49.156 - - [16/Jun/2026:00:20:02 +0100] POST /wp-login.php HTTP/1.1 301 3578 https://[REDACTED_DOMAIN]/wp-login.php Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:118.0) Gecko/20100101 Firefox/118.0
show less
Web App Attack
๐ฉ๐ช
F242
2026-06-14 19:09:25
(1 week ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2026-06-13 08:22:56
(1 week ago)
[server.tmg.gr] httpd-login-spray-site: sites=hacm.gr; logs=/var/log/httpd/domains/hacm.gr.log; samp ...
show more
[server.tmg.gr] httpd-login-spray-site: sites=hacm.gr; logs=/var/log/httpd/domains/hacm.gr.log; samples=site_wide=true | distinct_ips=20 | /wp-login.php
show less
Hacking
Web App Attack
Anonymous
2026-06-12 12:17:07
(1 week ago)
Brute forcing Wordpress login
Hacking
Web App Attack
๐ฌ๐ท
setupgr
2026-06-12 00:43:15
(1 week ago)
(mod_security) mod_security (id:900001) triggered by 104.207.49.156: 1 in the last 86400 secs; Ports ...
show more
(mod_security) mod_security (id:900001) triggered by 104.207.49.156: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Fri Jun 12 03:43:12.485712 2026] [security2:error] [pid 52835:tid 52913] [client 104.207.49.156:55191] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|alloweddomain2\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "74"] [id "900001"] [msg "Blocked WP Login attempt on domain: tavernadimitris.com"] [severity "CRITICAL"] [tag "security"] [hostname "tavernadimitris.com"] [uri "/wp-login.php"] [unique_id "aitWIGTUdRqWy5D9zgOwqgAAABM"], referer: https://tavernadimitris.com/wp-login.php
show less
Port Scan
Anonymous
2026-06-10 17:19:54
(1 week ago)
Web attack blocked by Wordfence on vestingstadvalkenburg.nl (1 hit). Reported by CRMON.
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-10 07:52:06
(1 week ago)
Wordfence waf block on kcuar
Web App Attack
Anonymous
2026-06-10 06:23:47
(1 week ago)
[server.tmg.gr] httpd-login-spray-site: sites=dunantcongress2022.gr; logs=/var/log/httpd/domains/dun ...
show more
[server.tmg.gr] httpd-login-spray-site: sites=dunantcongress2022.gr; logs=/var/log/httpd/domains/dunantcongress2022.gr.log; samples=site_wide=true | distinct_ips=20 | /wp-login.php
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 08:34:23
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 03:34:20.434813 2026] [security2:error] [pid 26391:tid 26414] [client 104.207.49.156:51263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howardhallis.com"] [uri "/.git/objects/10/cedabd4db46658c513e802612a9cf0e93ed369"] [unique_id "aalADAF_a2ciCSZOgi6_IAAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:20:35
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:20:31.649315 2026] [security2:error] [pid 20824:tid 20824] [client 104.207.49.156:42309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garantaconsulting.com"] [uri "/.git/config"] [unique_id "aYpPn1KnInwa2GZ2dFn-7AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:00:55
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-27 04:33:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 23:33:34.989019 2025] [security2:error] [pid 11750:tid 11750] [client 104.207.49.156:52871] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.alaskadreamspublishing.com"] [uri "/.git/HEAD"] [unique_id "aSfUnjD0PS1ZK1nI0F_u1gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 23:30:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 18:30:39.536815 2025] [security2:error] [pid 20709:tid 20709] [client 104.207.49.156:26561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mailserver.albertmassaad.com"] [uri "/.svn/wc.db"] [unique_id "aSeNnwE72uSrPjKGNJaRrAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack