π©πͺ
SMARTNET
2026-05-27 06:03:53
(3 weeks ago)
Aisuru(Mirai variant) DDoS | Incident ID: 8969aafa-3f20-493f-8883-3bda65a2b909
DDoS Attack
πΊπΈ
lostswordfish.com
2026-03-22 13:50:08
(2 months ago)
Wordfence waf block on robdarnell
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-02-12 00:58:42
(4 months ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer
... [wa02]
Bad Web Bot
Web App Attack
π³π±
oisecnet
2026-02-11 22:01:29
(4 months ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-02-11. 1 requests from this I ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-02-11. 1 requests from this IP.
show less
Brute-Force
Web App Attack
SSH
πΊπΈ
lostswordfish.com
2026-02-11 19:08:03
(4 months ago)
Wordfence waf block on robdarnell
Web App Attack
π·π΄
INTEQ
2026-02-11 15:46:37
(4 months ago)
Web attack from 138.204.79.233
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-02-11 15:28:22
(4 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
BR/Brazil/138-204-79-233.crnetfibra.com.br
Web App Attack
π©πͺ
stinpriza
2026-02-11 05:23:45
(4 months ago)
Web App Attack
Web App Attack
πΊπΈ
mnsf
2026-02-11 00:05:29
(4 months ago)
Xmlrpc Caught (6)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 20:55:14
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 138.204.79.233 (138-204-79-233.crnetfibra.com.b ...
show more
(mod_security) mod_security (id:225170) triggered by 138.204.79.233 (138-204-79-233.crnetfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 15:55:08.042036 2026] [security2:error] [pid 28209:tid 28209] [client 138.204.79.233:24774] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||3beeze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "3beeze.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYubLB7n3x42P1AnMHHu9AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 16:49:27
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 138.204.79.233 (138-204-79-233.crnetfibra.com.b ...
show more
(mod_security) mod_security (id:225170) triggered by 138.204.79.233 (138-204-79-233.crnetfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 11:49:20.469824 2026] [security2:error] [pid 21462:tid 21462] [client 138.204.79.233:24433] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stationrestaurant.ca|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stationrestaurant.ca"] [uri "/wp-json/wp/v2/users"] [unique_id "aYthkDXTGC4vgvBX4hAk3AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 07:15:23
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 138.204.79.233 (138-204-79-233.crnetfibra.com.b ...
show more
(mod_security) mod_security (id:225170) triggered by 138.204.79.233 (138-204-79-233.crnetfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 02:15:19.275070 2026] [security2:error] [pid 23248:tid 23248] [client 138.204.79.233:24372] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||losbarbarosdelnorte.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "losbarbarosdelnorte.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYrbB1u6j3QdlbC-IuBvTgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
0x44
2026-02-10 06:35:03
(4 months ago)
138.204.79.233 [10/Feb/2026] * Spam host detected, probing for vulnerabilities
Web Spam
Exploited Host
Web App Attack
π©πͺ
LRob.fr
2026-02-10 04:38:03
(4 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 23:13:51
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 138.204.79.233 (138-204-79-233.crnetfibra.com.b ...
show more
(mod_security) mod_security (id:225170) triggered by 138.204.79.233 (138-204-79-233.crnetfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:13:46.882513 2026] [security2:error] [pid 24909:tid 24909] [client 138.204.79.233:24843] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goatedlottosecrets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goatedlottosecrets.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYpqKgVarEIaS7_iBo1ZiAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack