๐ฉ๐ช
Ilop
2026-09-24 00:30:09
(1 day ago)
[hp-100] 19 unsolicited packets to honeypot ports 8000 (OCI DShield sensor)
Port Scan
๐ฉ๐ช
4server
2026-08-26 00:14:12
(4 weeks ago)
[WedAug2602:14:09.1191392026][security2:error][pid3168007:tid3168148][client122.8.95.113:0]ModSecuri ...
show more
[WedAug2602:14:09.1191392026][security2:error][pid3168007:tid3168148][client122.8.95.113:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.akastudio.ch\"][uri\"/\"][unique_id\"ao4v0UityHU5KvPWk3Oc3gAAANU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-06-14 21:04:07
(3 months ago)
WordPress login attempt
Brute-Force
๐จ๐ฆ
1gz
2026-06-04 13:32:33
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฆ
1gz
2026-06-03 09:14:24
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-06-02 01:32:39
(3 months ago)
(caddyscan) Scanner path probe from 122.8.95.113 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; D ...
show more
(caddyscan) Scanner path probe from 122.8.95.113 (SE/Sweden/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 122.8.95.113 - - [02/Jun/2026:01:32:32 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 122.8.95.113 - - [02/Jun/2026:01:32:33 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 122.8.95.113 - - [02/Jun/2026:01:32:34 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 122.8.95.113 - - [02/Jun/2026:01:32:37 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 122.8.95.113 - - [02/Jun/2026:01:32:37 +0000] "GET /wp-login.php HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-30 12:09:51
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 08:09:47.241623 2026] [security2:error] [pid 8797:tid 8797] [client 122.8.95.113:27231] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stardancertantra.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stardancertantra.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahrTi6naRodVmwVvZqxnYAAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 11:04:32
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 07:04:29.121828 2026] [security2:error] [pid 7204:tid 7204] [client 122.8.95.113:52061] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||philipma.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "philipma.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahrEPQ1lDDRPhPubYzJlpAAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 03:42:51
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 23:42:46.754475 2026] [security2:error] [pid 10518:tid 10518] [client 122.8.95.113:13541] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||krugmans.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "krugmans.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag5_NuW0rju26Zc1DGuMIAAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-05-13 17:58:52
(4 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 01:02:09
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 21:02:00.607802 2026] [security2:error] [pid 14849:tid 14849] [client 122.8.95.113:16143] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dwightbrown.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dwightbrown.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac3ACOTRMjEa8PbuFgKtSgAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 19:24:12
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 122.8.95.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 14:24:08.784421 2026] [security2:error] [pid 1209:tid 1209] [client 122.8.95.113:56443] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||futurbike.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "futurbike.it"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJ5WOS0Yw1f_4RKkFJpNAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack