๐ฒ๐ฝ
octageeks.com
2026-10-04 04:14:57
(3 days ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-29 04:24:49
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 13:59:55
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 09:59:36.675031 2026] [security2:error] [pid 25400:tid 25438] [client 130.49.77.73:62587] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||penboy7.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "penboy7.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ackwSLi3O6Hxna4tPPN23AAAABg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 02:50:01
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 22:49:57.650387 2026] [security2:error] [pid 21847:tid 21860] [client 130.49.77.73:33887] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sattraffic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sattraffic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acNNVZk4eqM36s2NGzBqHgAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-24 18:22:13
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 14:22:08.659049 2026] [security2:error] [pid 12844:tid 12844] [client 130.49.77.73:38735] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sinsky.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sinsky.net"] [uri "/wp-json/wp/v2/users"] [unique_id "acLWUEvEgOZcS_vlP8zQkwAAABg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-24 17:57:20
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 13:56:58.862179 2026] [security2:error] [pid 19751:tid 19751] [client 130.49.77.73:13023] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||varnadorefamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "varnadorefamily.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acLQahRJ72VItWkHog461AAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
mieg
2026-03-24 14:58:28
(6 months ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-login.php
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-23 11:40:02
(6 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:47:17
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:47:13.557544 2026] [security2:error] [pid 28127:tid 28127] [client 130.49.77.73:48307] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webjemm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webjemm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abvUMU7jC7g0434MRZZJLAAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-03-16 15:51:43
(6 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-06 23:23:26
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 18:23:22.956804 2026] [security2:error] [pid 30043:tid 30059] [client 130.49.77.73:62463] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||suncoastequipment.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "suncoastequipment.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aath6jo-CTUeEip5MWs2jQAAAE4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-03-03 20:22:44
(7 months ago)
130.49.77.73 - - [03/Mar/2026:13:22:44 -0700] "POST /wp-login.php HTTP/1.1" 200 2333 "https://dooce. ...
show more
130.49.77.73 - - [03/Mar/2026:13:22:44 -0700] "POST /wp-login.php HTTP/1.1" 200 2333 "https://dooce.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ฎ๐ฉ
RasyiidWho
2026-02-26 22:44:11
(7 months ago)
ip112.20 . 130.49.77.73 - - [27/Feb/2026:05:44:10 +0700] "POST /xmlrpc.php HTTP/1.1" 401 172 "-" "cu ...
show more
ip112.20 . 130.49.77.73 - - [27/Feb/2026:05:44:10 +0700] "POST /xmlrpc.php HTTP/1.1" 401 172 "-" "curl/7.88.1"
...
show less
DDoS Attack
Brute-Force
Port Scan
Bad Web Bot
Web App Attack
SSH
๐บ๐ธ
rsiddall
2026-02-26 14:39:41
(7 months ago)
130.49.77.73 - - [26/Feb/2026:09:39:38 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "curl/7.88.1" ...
show more
130.49.77.73 - - [26/Feb/2026:09:39:38 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "curl/7.88.1"
130.49.77.73 - - [26/Feb/2026:09:39:41 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Wget/1.21.4"
...
show less
Brute-Force
๐จ๐ญ
backslash
2026-02-22 03:42:00
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot