🇬🇧
Apache
2026-08-30 10:12:34
(13 hours ago)
(wplogin) WordPress login brute-force 142.111.152.109 (US/United States/-): 5 in the last 300 secs
Brute-Force
🇵🇱
Budyn
2026-08-28 08:30:26
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.ovh | URI: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇷🇸
Smel
2026-08-27 00:22:02
(3 days ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 23:14:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 142.111.152.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 142.111.152.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:13:31.884551 2026] [security2:error] [pid 5940:tid 5940] [client 142.111.152.109:65005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.43"] [uri "/backend/.env"] [unique_id "ao9zG4KFeUNzdigqgcuruAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 22:38:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 142.111.152.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 142.111.152.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 18:38:06.025661 2026] [security2:error] [pid 1778:tid 1778] [client 142.111.152.109:31909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.20"] [uri "/.env"] [unique_id "ao9qznVuKe2nmoY7G9B-MAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 16:49:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 142.111.152.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 142.111.152.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:48:48.123287 2026] [security2:error] [pid 4415:tid 4436] [client 142.111.152.109:49609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.129"] [uri "/protected/.env"] [unique_id "ao8Y8BC_uvzrkU5Ph4VGNAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
Halux
2026-08-26 15:35:16
(4 days ago)
142.111.152.109 Probing protected path or service
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 08:07:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 142.111.152.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 142.111.152.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:06:58.562102 2026] [security2:error] [pid 32074:tid 32152] [client 142.111.152.109:22881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.24"] [uri "/vendor/laravel/.env"] [unique_id "ao6eog7t6CTk0OK653MGUgAAAck"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
masterguru
2026-08-24 19:22:54
(6 days ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (5001900-122)
Web App Attack
🇹🇷
oalver
2026-08-24 16:17:02
(6 days ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-03. Risk score: 90/100.
show less
Web App Attack
🇫🇮
YF
2026-08-23 17:00:30
(1 week ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
Anonymous
2026-08-22 09:46:03
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-16 12:13:19
(2 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇮🇹
CoreTech srl
2026-08-16 06:08:56
(2 weeks ago)
cloudlinux2 fail2ban: 2026-08-16 08:04:49,683 fail2ban.filter [1791]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-16 08:04:49,683 fail2ban.filter [1791]: INFO [plesk-modsecurity] Found 105.235.130.128 - 2026-08-16 08:04:49cloudlinux2 fail2ban: 2026-08-16 08:05:09,337 fail2ban.actions [1791]: NOTICE [plesk-modsecurity] Ban 5.31.241.115cloudlinux2 fail2ban: 2026-08-16 08:05:09,343 fail2ban.filter [1791]: INFO [recidive] Found 5.31.241.115 - 2026-08-16 08:05:09cloudlinux2 fail2ban: 2026-08-16 08:05:09,111 fail2ban.filter [1791]: INFO [plesk-modsecurity] Found 5.31.241.115 - 2026-08-16 08:05:09cloudlinux2 fail2ban: 2026-08-16 08:05:34,268 fail2ban.filter [1791]: INFO [plesk-modsecurity] Found 104.22.93.94 - 2026-08-16 08:05:34cloudlinux2 fail2ban: 2026-08-16 08:05:36,066 fail2ban.filter [1791]: INFO [plesk-modsecurity] Found 105.235.130.128 - 2026-08-16 08:05:36cloudlinux2 fail2ban: 2026-08-16 08:05:34,255 fail2ban.filter [1791]: INFO [plesk-modsecurity] Found 104.22.93.94 - 2026-08-16 08:05:34cloudlinux2 fail2ban: 2026-08
show less
Web App Attack
🇦🇺
AWW-Admin
2026-08-15 09:50:08
(2 weeks ago)
(wordpress) Failed wordpress login from 142.111.152.109 (US/United States/-)
Brute-Force