Anonymous
2026-06-03 21:26:27
(3 days ago)
[osotir.org] httpd-login-spray-site: sites=agonistes.gr.synathlountes; logs=/var/log/httpd/domains/a ...
show more
[osotir.org] httpd-login-spray-site: sites=agonistes.gr.synathlountes; logs=/var/log/httpd/domains/agonistes.gr.synathlountes.log; samples=site_wide=true | distinct_ips=10 | /wp-login.php
show less
Hacking
Web App Attack
π«π·
ELYAZ
2026-05-30 23:43:24
(1 week ago)
(y4) Failed scan -byebye- from 104.207.54.96 (DE/Germany/-): (CF_ENABLE)
Hacking
π«π·
tilellit.pro
2026-05-30 03:45:05
(1 week ago)
Fail2Ban banned 104.207.54.96 for security violations in jail wp-armour. Log: 2026/05/30 03:45:05 [e ...
show more
Fail2Ban banned 104.207.54.96 for security violations in jail wp-armour. Log: 2026/05/30 03:45:05 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 104.207.54.96 | Target: wplogin" , client: 104.207.54.96, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
πΊπΈ
dtorrer
2026-05-29 21:36:54
(1 week ago)
Brute-force general attack.
Brute-Force
π«π·
ELYAZ
2026-05-26 23:39:00
(1 week ago)
(y4) Failed scan -byebye- from 104.207.54.96 (DE/Germany/-): (CF_ENABLE)
Hacking
π²π½
octageeks.com
2026-05-24 04:10:13
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
π¦πΊ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
π¦πΊ
screwlooseit.com.au
2026-03-03 22:35:19
(3 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack
π³π±
jjnxpct
2026-02-16 04:54:24
(3 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /v2/.git/config (Rule ID: 930130) - Restricted File Access Attempt
show less
Hacking
Web App Attack
Anonymous
2026-02-15 13:05:30
(3 months ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
Anonymous
2026-02-15 06:40:20
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.207.54.96 (DE/Germany/-)
SQL Injection
πΊπΈ
TPI-Abuse
2026-02-15 06:10:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:10:08.453958 2026] [security2:error] [pid 1836:tid 1865] [client 104.207.54.96:57063] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oneringnetwork.net"] [uri "/admin/.git/config"] [unique_id "aZFjQPaxUwTOactKDP5AFwAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 05:42:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:42:48.602243 2026] [security2:error] [pid 19698:tid 19698] [client 104.207.54.96:55627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scandicakes.com"] [uri "/.env.local"] [unique_id "aZFc2GXllzY0nqSt54xQJQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-02-15 04:21:54
(3 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 03:31:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:31:02.503842 2026] [security2:error] [pid 8577:tid 8577] [client 104.207.54.96:28085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nolaanimereviews.com"] [uri "/.env.staging"] [unique_id "aZE99qkl6ULm-KZ-sY1W7AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack