๐ณ๐ฑ
Site.eu
2026-06-26 06:45:41
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐จ๐ฆ
KIsmay
2026-06-26 03:42:44
(1 day ago)
Jun 25 23:42:04 www4 WPAudit[3200716]: 194.62.107.3 www.terencegower.com "Mozilla/5.0 (Windows NT 10 ...
show more
Jun 25 23:42:04 www4 WPAudit[3200716]: 194.62.107.3 www.terencegower.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36" julien:qwertyuiop FAIL
Jun 25 23:42:27 www4 WPAudit[3200710]: 194.62.107.3 www.terencegower.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36" julien:102030 FAIL
Jun 25 23:42:34 www4 WPAudit[3200717]: 194.62.107.3 www.terencegower.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36" julien:Qwerty123! FAIL
Jun 25 23:42:40 www4 WPAudit[3200716]: 194.62.107.3 www.terencegower.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36" julien:changeme1 FAIL
Jun 25 23:42:43 www4 WPAudit[3200715]: 194.62.107.3 www.terencegower.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-26 03:00:16
(1 day ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฒ๐น
Malta
2026-06-26 01:28:46
(1 day ago)
194.62.107.3 - - [26/Jun/2026:03:28:46 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Windows NT 1 ...
show more
194.62.107.3 - - [26/Jun/2026:03:28:46 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-06-26 00:23:38
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฌ๐ง
BRHosting
2026-06-25 23:53:02
(1 day ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
๐ซ๐ท
applemooz
2026-06-25 23:49:52
(1 day ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-25 21:40:29
(1 day ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 03:52:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 23:51:59.708704 2026] [security2:error] [pid 27413:tid 27413] [client 194.62.107.3:40143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.microdot.net"] [uri "/.env"] [unique_id "ajYOX3qiLV_jGtd5yayaWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-06-20 02:24:57
(1 week ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 23:33:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 19:33:40.502231 2026] [security2:error] [pid 6633:tid 6633] [client 194.62.107.3:32635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.assistfeed.com"] [uri "/.env"] [unique_id "ajSAVDT8OGU_BL2yBiK3_AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 18:05:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 14:05:37.902357 2026] [security2:error] [pid 23152:tid 23152] [client 194.62.107.3:41307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.glendaleheritage.org"] [uri "/.env"] [unique_id "ajQzcVvmrJ02VHRFLgNmOwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 16:43:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 12:43:16.620109 2026] [security2:error] [pid 13330:tid 13360] [client 194.62.107.3:40231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southtampaprints.com"] [uri "/.env"] [unique_id "ajQgJGDytWbfRLKxnSyjOAAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-18 14:13:48
(1 week ago)
194.62.107.3 - - [18/Jun/2026:17:13:48 +0300] "GET /.env HTTP/1.1" 404 4761 "-" "Mozilla/5.0 (Macint ...
show more
194.62.107.3 - - [18/Jun/2026:17:13:48 +0300] "GET /.env HTTP/1.1" 404 4761 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 13:08:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 09:08:05.377550 2026] [security2:error] [pid 16784:tid 16795] [client 194.62.107.3:42225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iamfluff.com"] [uri "/.env"] [unique_id "ajPttai_-Wv5oe2DdQ4ZRgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack