๐ฉ๐ช
pltcldvlpr
2026-07-20 19:17:25
(16 hours ago)
Bogus Useragent: 109.107.253.80 - - [20/Jul/2026:21:17:24 +0200] "GET /protocol?id=st_5_77¶graph ...
show more
Bogus Useragent: 109.107.253.80 - - [20/Jul/2026:21:17:24 +0200] "GET /protocol?id=st_5_77¶graph=14483676&seq=1259 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; MSIE 8.0; Windows CE; Trident/5.1)" asn=9038 org="Batelco Jordan" country=JO
...
show less
Bad Web Bot
๐บ๐ธ
stechusa
2026-07-18 08:05:03
(3 days ago)
ELEVATED_THREAT | 399 IPs targeting /brand.html | URL template shared by 177 IPs: /brand.html?bulb_s ...
show more
ELEVATED_THREAT | 399 IPs targeting /brand.html | URL template shared by 177 IPs: /brand.html?bulb_shape=*&bulb_shape_type=*&bulb_type=*&mode=list&p=* | Facet request during elevated threat (facet_ratio=0.98, unique_ips=586)
show less
Bad Web Bot
DDoS Attack
๐ซ๐ท
vtchost.com
2026-05-08 03:47:05
(2 months ago)
requested honeypot page - ignored robots.txt - scraping botnet or virus
...
Bad Web Bot
Exploited Host
๐จ๐ญ
backslash
2026-04-07 12:33:01
(3 months ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-24 17:52:54
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 109.107.253.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 109.107.253.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 13:52:45.779091 2026] [security2:error] [pid 30710:tid 30710] [client 109.107.253.80:43748] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.player-care.com|F|2"] [data ".spencerserolls.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.player-care.com"] [uri "/cb/www.spencerserolls.com"] [unique_id "acLPbVR6QFByYL0x4D8AcAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-03-16 22:50:41
(4 months ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
๐บ๐ธ
Penny Packer
2026-03-15 08:24:11
(4 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 08:23:44
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 109.107.253.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 109.107.253.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 04:23:39.522613 2026] [security2:error] [pid 32753:tid 32753] [client 109.107.253.80:42323] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lasertherapyoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lasertherapyoc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abZsi8WrwtbC0GaGoY603gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-03-15 08:00:07
(4 months ago)
(wordpress) Failed wordpress login from 109.107.253.80 (JO/Jordan/-): (CF_ENABLE)
Brute-Force
๐ง๐ช
cmbplf
2026-03-15 07:31:25
(4 months ago)
1.525 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ณ๐ฟ
Tripwire
2026-03-12 10:36:38
(4 months ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2026-03-12 07:19:43
(4 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฉ๐ช
abdubhai
2026-03-12 06:31:20
(4 months ago)
109.107.253.80 - - [12/Mar/2026:
...
Brute-Force
๐ฉ๐ช
Bedios GmbH
2026-03-10 10:06:11
(4 months ago)
Wordpress hacking attempt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 10:20:17
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 109.107.253.80 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 109.107.253.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 06:20:10.235977 2026] [security2:error] [pid 13290:tid 13290] [client 109.107.253.80:42850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rajabarber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rajabarber.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aa6e2nRMQIWU8sdm_Njx7gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack