๐ณ๐ด
jad-abuse
2026-09-01 04:09:38
(11 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-09-01 02:27:00
(12 hours ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-08-31 11:08:56
(1 day ago)
cloudlinux2 fail2ban: 2026-08-31 13:03:50,294 fail2ban.filter [1605]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-31 13:03:50,294 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 59.92.46.149 - 2026-08-31 13:03:50cloudlinux2 fail2ban: 2026-08-31 13:03:56,443 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 104.207.59.107 - 2026-08-31 13:03:55cloudlinux2 fail2ban: 2026-08-31 13:03:57,232 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 65.111.27.16 - 2026-08-31 13:03:56cloudlinux2 fail2ban: 2026-08-31 13:03:57,882 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 217.181.90.83 - 2026-08-31 13:03:57cloudlinux2 fail2ban: 2026-08-31 13:04:05,890 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 57.131.41.149 - 2026-08-31 13:04:05cloudlinux2 fail2ban: 2026-08-31 13:04:26,724 fail2ban.filter [1605]: INFO [recidive] Found 45.3.55.198 - 2026-08-31 13:04:26cloudlinux2 fail2ban: 2026-08-31 13:04:26,661 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 104.207.58.251 - 2026-08-31 13:04:26cloudlinux2 fail
show less
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-31 03:26:35
(1 day ago)
(wordpress) Failed wordpress login from 104.207.59.107 (CA/Canada/-): (CF_ENABLE)
Brute-Force
๐ฎ๐น
VHosting
2026-08-23 09:30:04
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-10 22:58:10
(3 weeks ago)
WordPress probing | req: /xmlrpc.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebK ...
show more
WordPress probing | req: /xmlrpc.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15
show less
Brute-Force
Web App Attack
Anonymous
2026-07-01 08:33:42
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.207.59.107 (CA/Canada/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-02-11 22:35:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 17:35:18.796358 2026] [security2:error] [pid 5088:tid 5088] [client 104.207.59.107:10743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aridscapes.com"] [uri "/api/.env"] [unique_id "aY0EJqbkuXq5x12LY3aWEQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 05:42:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:42:05.240895 2026] [security2:error] [pid 5921:tid 5921] [client 104.207.59.107:34491] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kochcreative.com"] [uri "/.env"] [unique_id "aYrFLQ4OHdnC7GnQfXT9YwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 05:04:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:04:44.784287 2026] [security2:error] [pid 24752:tid 24752] [client 104.207.59.107:11993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kmnr.net"] [uri "/app/.git/config"] [unique_id "aYq8bM0rtQHV1EK4QBw6TgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:34:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:34:20.557995 2026] [security2:error] [pid 23402:tid 23402] [client 104.207.59.107:9623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hughhart.com"] [uri "/.env.production"] [unique_id "aYp9DJzp-DzxAL86h-cdeAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 21:51:20
(6 months ago)
Blocking for trying to access an exploit file: /config/.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 21:12:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:12:10.418912 2026] [security2:error] [pid 23450:tid 23450] [client 104.207.59.107:25421] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horizonsoundchicago.com"] [uri "/admin/.env"] [unique_id "aYpNqhfNNbsET39LbOD1AgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-05 20:38:09
(7 months ago)
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 9 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
๐ช๐ธ
librebit
2025-12-30 11:06:15
(8 months ago)
Brute force
Brute-Force