🇬🇧
sandra361
2026-08-30 10:09:32
(1 week ago)
Port scan detected: 71 attempts across 1 port (53250). | Evidence: GHOST_SCAN: IN=enp1s0f0 SRC=138.1 ...
show more
Port scan detected: 71 attempts across 1 port (53250). | Evidence: GHOST_SCAN: IN=enp1s0f0 SRC=138.199.2.145 LEN=60 TOS=0x00 PREC=0x00 TTL=50 ID=2605 DF PROTO=TCP SPT=34324 DPT=53250 WINDOW=64240 RES=0x00 SYN URGP=0
show less
Port Scan
🇺🇸
TPI-Abuse
2025-11-09 11:06:20
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 09 06:06:16.113010 2025] [security2:error] [pid 8222:tid 8222] [client 138.199.2.145:38522] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||siczewicz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "siczewicz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRB1qEeBLibgYmrKSAvhYQAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-09 10:27:27
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 09 05:27:20.878164 2025] [security2:error] [pid 15946:tid 15946] [client 138.199.2.145:65090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naominixon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRBsiBtVECMohwoKIjQZxwAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-07 03:00:14
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 22:00:02.380913 2025] [security2:error] [pid 3380:tid 3380] [client 138.199.2.145:24998] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||homenetserv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "homenetserv.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ1gskpB7BNCX9JdlnUt-AAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2025-11-06 22:51:37
(10 months ago)
Web password guessing
Brute-Force
🇳🇱
Roderic
2025-11-06 21:46:43
(10 months ago)
(apache_scanners-2) Failed apache-scanners trigger with match [redacted])
Port Scan
🇺🇸
TPI-Abuse
2025-11-06 18:22:43
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 13:22:36.006755 2025] [security2:error] [pid 3221836:tid 3221836] [client 138.199.2.145:38896] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wilsontribe.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wilsontribe.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aQznbDdbawbsIktqkFJZ-QAAABg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-06 17:40:25
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 12:40:19.882177 2025] [security2:error] [pid 27358:tid 27358] [client 138.199.2.145:28148] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||williamcline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "williamcline.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQzdg0RK0_igp8Ro5MKn3AAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2025-11-06 16:35:06
(10 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-06 06:41:36
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 01:41:29.068398 2025] [security2:error] [pid 2258:tid 2258] [client 138.199.2.145:32882] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodpage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodpage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQxDGReCZTYJh-sUcEsEYAAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-03 20:33:55
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 138.199.2.145 (unn-138-199-2-145.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 03 15:33:47.758245 2025] [security2:error] [pid 29781:tid 29781] [client 138.199.2.145:41084] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||misterflores.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "misterflores.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQkRq0P-ZYI5bnyyShMX-wAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2025-11-03 12:20:11
(10 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2025-08-04 15:30:31
(1 year ago)
Botnet - login attempts with leaked random user/pass lists
Hacking
Brute-Force
Web App Attack
🇳🇱
maris.nl
2025-04-28 16:07:44
(1 year ago)
Part of a botnet which is attacking our services at slower endpoints.
DDoS Attack
🇪🇸
saima.info
2024-02-05 10:33:11
(2 years ago)
Port scanning, proxy abuse
Port Scan
Brute-Force