๐ฌ๐ง
consul.to
2026-03-28 14:00:11
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-03-21 22:44:03
(3 months ago)
2026-03-21 @ 23:44:02 (CET) ~ Blocked for trying to access: /wp-includes/ID3/license.txt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 16:01:26
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 102.129.252.222 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 102.129.252.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 12:01:17.540640 2026] [security2:error] [pid 19197:tid 19210] [client 102.129.252.222:50688] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.abusaimeh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.abusaimeh.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "abrMTePvTv9dIIMW5vXj8gAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 07:55:49
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 102.129.252.222 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 102.129.252.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 03:55:41.834989 2026] [security2:error] [pid 7361:tid 7361] [client 102.129.252.222:36164] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||magnoliahillproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "magnoliahillproductions.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "abpafRL-yqvC217cTb4rqAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Major Hostility
2026-03-17 15:30:09
(3 months ago)
"GET /wp-includes/ID3/license.txt HTTP/1.1" 404
"GET /feed/ HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/ ...
show more
"GET /wp-includes/ID3/license.txt HTTP/1.1" 404
"GET /feed/ HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2020/wp-includes/wlwmanifest.xml HTTP/1.1" 404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-17 11:46:27
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 102.129.252.222 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 102.129.252.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 17 07:46:20.828265 2026] [security2:error] [pid 24673:tid 24673] [client 102.129.252.222:59721] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||magazine.angelabcomics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "magazine.angelabcomics.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "abk_DGNURVGpM6Wnq1J6EQAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-03-17 01:05:10
(3 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐จ๐ญ
YF
2026-03-17 01:05:02
(3 months ago)
Unauthorized WordPress access attempt
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-03-17 00:34:04
(3 months ago)
613 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
๐จ๐ญ
zynex
2026-03-16 23:29:46
(3 months ago)
URL Probing: /wp1/wp-includes/wlwmanifest.xml
Web App Attack
๐ฉ๐ช
grassau.com
2026-03-16 22:00:08
(3 months ago)
*Port Scan* detected from 102.129.252.222 (US/United States/California/Santa Clara/-).
Port Scan
๐ฆ๐บ
oncord
2026-02-16 12:20:30
(4 months ago)
Form spam
Web Spam
๐บ๐ธ
xmission.com
2025-08-12 22:35:40
(10 months ago)
Blocked by UFW (TCP on 35100)
Source port: 62481
TTL: 56
Packet length: 52
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 35100)
Source port: 62481
TTL: 56
Packet length: 52
TOS: 0x08
This report (for 102.129.252.222) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐น๐ญ
thaizone.com
2025-06-16 06:24:02
(1 year ago)
Mail credential brute-force attack (SM3) #1
Email Spam
Brute-Force
๐ฉ๐ช
marzzzello
2025-05-16 05:09:00
(1 year ago)
Ports: 5x 35884
Port Scan