๐บ๐ธ
mnsf
2026-06-17 00:30:15
(8 hours ago)
Abuse Detected (1)
Brute-Force
Web App Attack
Anonymous
2026-06-16 17:34:31
(15 hours ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/install.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 06:33:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 02:33:07.845756 2026] [security2:error] [pid 14050:tid 14050] [client 104.23.221.113:12155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahamllc.com"] [uri "/.git/config"] [unique_id "ajDuI4b_qGphjroha54aDQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski
2026-06-14 19:56:49
(2 days ago)
IVski WAF | WordPress scanner detected - probing wp-content, xmlrpc or wp-login
Port Scan
Brute-Force
Web App Attack
๐จ๐ฆ
polycoda
2026-06-10 22:22:55
(6 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ณ๐ด
jad-abuse
2026-06-09 16:34:54
(1 week ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Ob ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 09:32:50
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 05:32:45.814852 2026] [security2:error] [pid 31284:tid 31310] [client 104.23.221.113:9751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eldebslaw.com"] [uri "/.git/config"] [unique_id "ahF0PRzfcIvD01wYBIUdfAAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 08:12:32
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 04:12:24.095860 2026] [security2:error] [pid 30668:tid 30668] [client 104.23.221.113:10085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "36quant.com"] [uri "/.git/config"] [unique_id "ahFhaCqPLwTojHoQCwSE7AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 02:05:10
(4 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ฆ
dispensight
2026-05-20 01:08:06
(4 weeks ago)
ngrok traffic to help.dispensight.cloud: 2 req(s) [GET:2] URIs: /. UA-class: WordPress. UA: http://d ...
show more
ngrok traffic to help.dispensight.cloud: 2 req(s) [GET:2] URIs: /. UA-class: WordPress. UA: http://dispensight.help/wp-admin/install.php?step=1. Geo: Sweden / Cloudflare, Inc.. Flags: proxy, threats:bot. Window: 2026-05-19T10:33:25-07:00 to 2026-05-19T18:08:06-07:00.
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-17 19:23:09
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 15:23:02.877351 2026] [security2:error] [pid 9506:tid 9506] [client 104.23.221.113:14005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "klnjp.kylight.net"] [uri "/.git/config"] [unique_id "agoVlo2bzZqjYfod8OSfHAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 15:27:06
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 11:27:00.895656 2026] [security2:error] [pid 27410:tid 27410] [client 104.23.221.113:13902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nealandmichaeledesign.com"] [uri "/.git/config"] [unique_id "agneRMK6i4FSpvLMRuznEAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-05-16 17:33:36
(1 month ago)
WordPress install scanner caught by honeydomain (dispensight.help): bot probed honeydomain TLD, was ...
show more
WordPress install scanner caught by honeydomain (dispensight.help): bot probed honeydomain TLD, was 301-redirected to canonical dispensight.com (path stripped), exposing target domain via User-Agent. 2 req(s). Honeydomain network operated for passive WP scanner attribution.. Target: help.dispensight.cloud. UA: http://dispensight.help/wp-admin/install.php?step=1. HTTP 400. Origin: Sweden / Cloudflare, Inc.. Detected by SecureLeaf ngrok monitor.
show less
Bad Web Bot
๐จ๐ฆ
dispensight
2026-05-15 19:50:07
(1 month ago)
Automated WordPress exploit probe caught via honeydomain infrastructure. Bot used http://dispensight ...
show more
Automated WordPress exploit probe caught via honeydomain infrastructure. Bot used http://dispensight.help/wp-admin/install.php?step=1 as User-Agent. Honeydomain operator-controlled bait; confirmed malicious WordPress scanner. Cloudflare Sweden proxy.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-13 11:49:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.221.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 07:49:30.490568 2026] [security2:error] [pid 29898:tid 29922] [client 104.23.221.113:13684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aafm.org"] [uri "/.env.save"] [unique_id "agRlSoq2Ooyi_L2bIJGwUQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack