๐ฌ๐ง
gigatech
2026-09-07 17:40:03
(1 week ago)
Webserver Probing
Web App Attack
๐ซ๐ฎ
YF
2026-09-07 17:30:32
(1 week ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 16:51:47
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:51:41.898250 2026] [security2:error] [pid 14098:tid 14098] [client 104.167.197.54:60122] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.davesievers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.davesievers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap7rnduk_lg8Wxct9lbllwAAAA0"], referer: https://t.co/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-07 14:48:25
(1 week ago)
levellagiftware.com.au:443 104.167.197.54 - - [08/Sep/2026:00:48:22 +1000] "GET /?author=1 HTTP/1.1" ...
show more
levellagiftware.com.au:443 104.167.197.54 - - [08/Sep/2026:00:48:22 +1000] "GET /?author=1 HTTP/1.1" 404 188890 "https://www.google.com/search?q=wordpress" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:118.0) Gecko/20100101 Firefox/118.0"
...
show less
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-07 14:10:48
(1 week ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 104.167.197.54 (US/United States/-)
Brute-Force
๐ซ๐ท
dynamix
2026-09-07 13:22:19
(1 week ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 13:04:33
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:04:28.122340 2026] [security2:error] [pid 2629:tid 2629] [client 104.167.197.54:58399] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prostar.industries"] [uri "/wp-json/wp/v2/users"] [unique_id "ap62XMIFSLCLaWuz4DwjIwAAABA"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-07 13:04:27
(1 week ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-07 12:38:31
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:38:24.152747 2026] [security2:error] [pid 7484:tid 7484] [client 104.167.197.54:60631] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.247.fishing|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.247.fishing"] [uri "/wp-json/wp/v2/users"] [unique_id "ap6wQAtQ-ei_A-kWm0mJEQAAAAs"], referer: https://t.co/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 10:58:12
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:58:04.520443 2026] [security2:error] [pid 30131:tid 30131] [client 104.167.197.54:52281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michaelthompson.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michaelthompson.biz"] [uri "/wp-json/wp/v2/users"] [unique_id "ap6YvIo-P3Sey03lSxmxAQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 10:26:13
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.167.197.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:26:06.917737 2026] [security2:error] [pid 1775984:tid 1776019] [client 104.167.197.54:49918] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||property-management-companies-chicago.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "property-management-companies-chicago.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap6RPj3uG9XAoZBWO-givAAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
masterguru
2026-09-07 07:06:02
(1 week ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-185)
Hacking
Anonymous
2026-09-06 02:12:27
(1 week ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Auto ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Automated scanning
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-05 11:15:45
(1 week ago)
๐ Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack
Anonymous
2026-09-05 07:00:07
(1 week ago)
IP banned by Fail2Ban in jail wordpress
Web App Attack
Brute-Force
Bad Web Bot