๐ซ๐ท
j-tap
2026-10-04 09:34:43
(1 day ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
๐บ๐ธ
drewf.ink
2026-09-28 23:57:41
(6 days ago)
[23:57] Attempted HTTPS GlobalProtect config retrieval with credentials ajimenez:Pa*****d1 (getconfi ...
show more
[23:57] Attempted HTTPS GlobalProtect config retrieval with credentials ajimenez:Pa*****d1 (getconfig.esp - some brute-force tooling targets this directly instead of login.esp)
show less
Web App Attack
๐จ๐ฟ
Countryman
2026-09-04 00:10:01
(1 month ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐ธ๐ช
OnTheEdge
2026-09-03 11:45:35
(1 month ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ช๐ธ
librebit
2026-06-24 03:20:11
(3 months ago)
Brute force
Brute-Force
๐ฌ๐ง
Apache
2026-03-21 01:05:07
(6 months ago)
(mod_security) mod_security (id:210410) triggered by 104.207.61.161 (CA/Canada/-): 5 in the last 300 ...
show more
(mod_security) mod_security (id:210410) triggered by 104.207.61.161 (CA/Canada/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:39:44
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:39:38.592552 2026] [security2:error] [pid 32228:tid 32228] [client 104.207.61.161:38995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gamepart.com"] [uri "/admin/.env"] [unique_id "aYpGCu96ohVxyFXNyN4zdwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 18:28:28
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 13:28:21.194157 2026] [security2:error] [pid 7970:tid 7970] [client 104.207.61.161:27763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "futureproductionsonline.com"] [uri "/frontend/.env"] [unique_id "aYonRTE9Dj9JiIajGjRhVgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 17:57:58
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 12:57:43.208015 2026] [security2:error] [pid 18212:tid 18212] [client 104.207.61.161:46747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furballrecords.com"] [uri "/.env.production"] [unique_id "aYogF5J5THROqHOAE89FMwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 12:00:09
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 07:00:02.274699 2026] [security2:error] [pid 9861:tid 9861] [client 104.207.61.161:40939] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galvez.cc"] [uri "/admin/.git/config"] [unique_id "aYnMQnCb_2T2VaJ9p3pVUwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 10:19:43
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.61.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 05:19:40.304749 2026] [security2:error] [pid 26155:tid 26155] [client 104.207.61.161:26709] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gactennisacademy.org"] [uri "/admin/.env"] [unique_id "aYm0vNCCAoiiW3PaYRMHJwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-02-09 09:51:49
(7 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-01-05 13:46:51
(9 months ago)
Infected user bad webscan
Exploited Host
Anonymous
2025-11-26 23:44:39
(10 months ago)
Attempted brute force login to web vpn 19 time(s); last attempt for 2025.11.26 is noted in report ti ...
show more
Attempted brute force login to web vpn 19 time(s); last attempt for 2025.11.26 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฒ๐พ
syokadmin
2025-11-25 12:55:22
(10 months ago)
(cpanel) Failed cPanel login from 104.207.61.161 (CA/Canada/-): 1 in the last 3600 secs
Brute-Force
Web App Attack