๐บ๐ธ
TPI-Abuse
2026-06-28 23:40:20
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 103.169.161.70 (pa380.positiveserver.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 103.169.161.70 (pa380.positiveserver.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 19:40:05.144915 2026] [security2:error] [pid 15002:tid 15002] [client 103.169.161.70:43196] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frogdesignmexico.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frogdesignmexico.com"] [uri "/wp-json/wp/v2/users/5"] [unique_id "akGw1e8YHGmhevRfsaiEVwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-28 19:09:45
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-19 20:40:12
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-12 20:42:53
(2 weeks ago)
Try to access /haardhout-emmeloord//xmlrpc.php
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-12 18:32:13
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 11:24:19
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.169.161.70 (pa380.positiveserver.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 103.169.161.70 (pa380.positiveserver.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 07:24:13.297946 2026] [security2:error] [pid 18537:tid 18537] [client 103.169.161.70:41576] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lumentravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lumentravel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aivsXaoxwCZmdBJkh7c3YgAAAAw"], referer: https://lumentravel.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:53:16
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.169.161.70 (pa380.positiveserver.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 103.169.161.70 (pa380.positiveserver.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:53:07.817159 2026] [security2:error] [pid 28440:tid 28440] [client 103.169.161.70:47916] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.avaliantlife.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aivXA7o5C6A1ht-oGIN-WgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-11 08:24:04
(2 weeks ago)
Wordfence waf block on registrymatters
Web App Attack
๐ฒ๐น
Malta
2026-06-11 04:17:35
(2 weeks ago)
103.169.161.70 - - [11/Jun/2026:06:17:35 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintos ...
show more
103.169.161.70 - - [11/Jun/2026:06:17:35 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐ซ๐ท
LRob.fr
2026-06-10 15:45:03
(2 weeks ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฌ๐ง
spamverify.com
2026-06-07 11:44:01
(3 weeks ago)
Honeypot Hit: xmlrpc.php
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 07:03:39
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.169.161.70 (pa380.positiveserver.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 103.169.161.70 (pa380.positiveserver.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 03:03:34.346859 2026] [security2:error] [pid 31115:tid 31115] [client 103.169.161.70:42130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||genevainvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "genevainvestors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiUXxjZygv8TS5-_ban1QwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-06-06 22:41:54
(3 weeks ago)
103.169.161.70 - - [07/Jun/2026:00:41:54 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; ...
show more
103.169.161.70 - - [07/Jun/2026:00:41:54 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
Anonymous
2026-06-04 03:00:06
(3 weeks ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-03 17:56:03
(3 weeks ago)
Wordfence waf block on parsol
Web App Attack