🇳🇿
Tripwire
2026-09-09 07:56:50
(1 hour ago)
Wordpress login attempts
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:39:58
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.teleko ...
show more
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:39:54.314490 2026] [security2:error] [pid 23938:tid 23938] [client 109.93.191.47:21661] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||advantagept.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "advantagept.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDjGt6hQQrcj87RiEnK5AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-09 04:13:09
(5 hours ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 47.191.93.109.rbl.malwa ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 47.191.93.109.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-09 03:53:58
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.teleko ...
show more
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:53:53.419009 2026] [security2:error] [pid 7290:tid 7290] [client 109.93.191.47:22386] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talkingmess.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talkingmess.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDYUSdYhxdeMYnGyb3x-QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:34:44
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.teleko ...
show more
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:34:38.677855 2026] [security2:error] [pid 12438:tid 12438] [client 109.93.191.47:21572] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||natickvillagerentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "natickvillagerentals.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDTzpwsPdpbAS-ftGk7FwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:08:32
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.teleko ...
show more
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:08:29.683228 2026] [security2:error] [pid 28852:tid 28852] [client 109.93.191.47:21844] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theaccentsnet2019.mainstreetofficesuites.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theaccentsnet2019.mainstreetofficesuites.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC_nYTh2xW2XU-Lr9ievAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:46:07
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.teleko ...
show more
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:46:01.796128 2026] [security2:error] [pid 30962:tid 30962] [client 109.93.191.47:22281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.blog.post-therapyreconditioning.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.blog.post-therapyreconditioning.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC6WaUjmW7uC-GqeDpzxAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 23:28:19
(10 hours ago)
109.93.191.47 - - [09/Sep/2026:01:28:14 +0200] "GET /wp-login.php HTTP/2.0" 200 4321 "-" "Mozilla/5. ...
show more
109.93.191.47 - - [09/Sep/2026:01:28:14 +0200] "GET /wp-login.php HTTP/2.0" 200 4321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇷🇴
SpamStopper
2026-09-08 21:36:04
(12 hours ago)
Fail2Ban - WP Spoofing
Port Scan
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 18:34:44
(15 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:54:06
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.teleko ...
show more
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:54:01.391246 2026] [security2:error] [pid 11502:tid 11502] [client 109.93.191.47:21623] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rame-int.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rame-int.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBLuQ8yENw4VBF7P8jUnwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:27:28
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.teleko ...
show more
(mod_security) mod_security (id:225170) triggered by 109.93.191.47 (109-93-191-47.dynamic.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:27:22.547944 2026] [security2:error] [pid 20503:tid 20503] [client 109.93.191.47:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.southernbroadcast.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqANOtgeBbe42xSMbCllLgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Oakley
2026-05-26 13:09:08
(3 months ago)
(confirmed_bot_sig) Confirmed bot
Hacking
🇭🇺
ksol-hostmaster
2025-10-19 20:27:55
(10 months ago)
Massive botnet baited into scraping tarpit
Bad Web Bot
🇩🇪
bescared
2024-10-28 03:21:00
(1 year ago)
Malicious activity detected: URL probing.
Hacking
Bad Web Bot
Web App Attack