🇩🇪
ghostwarriors
2026-09-03 13:20:16
(6 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ambor
2026-09-03 12:32:19
(6 days ago)
Honeypot access: PHP file scan attempt: //xmlrpc.php. Path: //xmlrpc.php
Web App Attack
Anonymous
2026-09-03 12:31:11
(6 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇮🇹
VHosting
2026-09-03 12:05:09
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
CounterScrape
2026-07-06 00:11:20
(2 months ago)
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapp ...
show more
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapped in honeypot. Concurrency hits: 2. Bandwidth drained: 2.3 MB.
show less
Bad Web Bot
Port Scan
🇺🇸
CounterScrape
2026-07-05 00:05:59
(2 months ago)
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapp ...
show more
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapped in honeypot. Concurrency hits: 2. Bandwidth drained: 2.3 MB.
show less
Bad Web Bot
Port Scan
🇧🇪
cmbplf
2026-07-04 10:35:32
(2 months ago)
1.802 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-04 02:04:21
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 149.102.233.187 (unn-149-102-233-187.datapacket ...
show more
(mod_security) mod_security (id:225170) triggered by 149.102.233.187 (unn-149-102-233-187.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 22:04:14.735695 2026] [security2:error] [pid 2419:tid 2419] [client 149.102.233.187:50989] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.mahjongcouture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.mahjongcouture.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aff-nltI_j3jy070sOsJSAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇳
ThreatBook.io
2026-04-16 23:48:45
(4 months ago)
ThreatBook Intelligence: Zombie,Mobile more details on https://threatbook.io/ip/149.102.233.187
2026 ...
show more
ThreatBook Intelligence: Zombie,Mobile more details on https://threatbook.io/ip/149.102.233.187
2026-04-16 13:11:04 /
2026-04-16 13:11:10 /website/wp-includes/wlwmanifest.xml
2026-04-16 13:11:05 /wp-includes/wlwmanifest.xml
2026-04-16 13:11:07 /
2026-04-16 13:11:09 /web/wp-includes/wlwmanifest.xml
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-04-16 10:23:18
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 149.102.233.187 (unn-149-102-233-187.datapacket ...
show more
(mod_security) mod_security (id:225170) triggered by 149.102.233.187 (unn-149-102-233-187.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 06:23:11.459152 2026] [security2:error] [pid 2845439:tid 2845439] [client 149.102.233.187:65309] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drdot.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drdot.xyz"] [uri "/wp-json/wp/v2/users/"] [unique_id "aeC4j8C7V4YeD4umftb6bgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-16 08:07:55
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 149.102.233.187 (unn-149-102-233-187.datapacket ...
show more
(mod_security) mod_security (id:225170) triggered by 149.102.233.187 (unn-149-102-233-187.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 04:07:49.255133 2026] [security2:error] [pid 2402264:tid 2402264] [client 149.102.233.187:56488] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mlsdirect.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mlsdirect.xyz"] [uri "/wp-json/wp/v2/users/"] [unique_id "aeCY1adTbHURtbBOBGI-7QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-04-16 07:33:03
(4 months ago)
[redacted] 149.102.233.187 - - [16/Apr/2026:08:33:01 +0100] "GET //wp-includes/[redacted] HTTP/1.1" ...
show more
[redacted] 149.102.233.187 - - [16/Apr/2026:08:33:01 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 302 5282 0/60341 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" [redacted] 149.102.233.187 - - [16/Apr/2026:08:33:01 +0100] "GET //[redacted]?rsd HTTP/1.1" 302 1554 0/74396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-04-16 07:16:38
(4 months ago)
Web vulnerability probing: //wordpress/wp-includes/wlwmanifest.xml
Web App Attack
🇧🇾
lns.bz
2026-04-16 05:51:01
(4 months ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-04-16 03:10:08
(4 months ago)
[Thu Apr 16 05:10:06.157592 2026] [authz_core:error] [pid 465528:tid 465541] [client 149.102.233.187 ...
show more
[Thu Apr 16 05:10:06.157592 2026] [authz_core:error] [pid 465528:tid 465541] [client 149.102.233.187:53786] AH01630: client denied by server configuration: /var/www/html/
[Thu Apr 16 05:10:06.486294 2026] [authz_core:error] [pid 465528:tid 465547] [client 149.102.233.187:53786] AH01630: client denied by server configuration: /var/www/html/
[Thu Apr 16 05:10:06.814155 2026] [authz_core:error] [pid 465528:tid 465548] [client 149.102.233.187:53786] AH01630: client denied by server configuration: /var/www/html/wp-includes
[Thu Apr 16 05:10:07.143967 2026] [authz_core:error] [pid 465528:tid 465549] [client 149.102.233.187:53786] AH01630: client denied by server configuration: /var/www/html/xmlrpc.php
[Thu Apr 16 05:10:07.472684 2026] [authz_core:error] [pid 465528:tid 465540] [client 149.102.233.187:53786] AH01630: client denied by server configuration: /var/www/html/
...
show less
Web App Attack