🇨🇦
DRI
2026-07-28 22:38:37
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
🇺🇸
TPI-Abuse
2026-07-15 07:05:48
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 03:05:40.844916 2026] [security2:error] [pid 9452:tid 9452] [client 157.22.18.180:36139] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kwijlen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kwijlen.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alcxRFeD51OzL0QQtWvsuQAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-07-10 21:59:17
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
oralunal
2026-07-07 18:18:31
(2 months ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
🇧🇪
Saec
2026-06-30 17:15:06
(2 months ago)
Jarvis auto-ban: CF honeypot path /xmlrpc.php (3× on saec.me)
Port Scan
Web App Attack
🇺🇸
TRoden
2026-06-23 22:01:15
(2 months ago)
Geo Block Plugin: Escalation flag(s): rce_attempt
Hacking
🇩🇪
big-cloud.nl
2026-04-11 07:59:49
(5 months ago)
Try to access /xmlrpc.php
Web App Attack
🇦🇺
MAGIC
2026-04-09 00:20:26
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-28 01:13:55
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 21:13:50.197791 2026] [security2:error] [pid 18812:tid 18812] [client 157.22.18.180:62097] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stormwlf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stormwlf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "accrTia3qGmZSJmTtK6jvgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-27 20:52:22
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 16:52:16.266420 2026] [security2:error] [pid 22691:tid 22691] [client 157.22.18.180:59281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mitchellamazing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mitchellamazing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acbuALjZ0ZeYEjkBi59D1gAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-03-26 20:21:58
(5 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-22 10:09:45
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.18.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.18.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 06:09:38.618975 2026] [security2:error] [pid 12464:tid 12464] [client 157.22.18.180:39827] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yogitunes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yogitunes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab-_4gLnQGXPy2pNlWstxgAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kjaerulff
2026-03-03 21:03:04
(6 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
🇩🇪
Packets-Decreaser.NET
2025-12-10 14:34:54
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam