๐ฆ๐บ
FSB.ru - Is it?
2026-06-08 05:07:22
(1 hour ago)
Brute force login for honeypot user accounts
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 23:35:14
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 160.25.5.253 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 160.25.5.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 19:35:02.832036 2026] [security2:error] [pid 21738:tid 21738] [client 160.25.5.253:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.rodrigoaldecoa.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiYAJkFbXKK4Ifap7-54iQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 17:18:14
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 160.25.5.253 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 160.25.5.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 13:18:09.855253 2026] [security2:error] [pid 28791:tid 28791] [client 160.25.5.253:32796] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dev.jeanniemorrislaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dev.jeanniemorrislaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiWn0WerysX0G1ZI0h8UJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-05 02:08:03
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 23:05:27
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 160.25.5.253 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 160.25.5.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 19:05:22.166966 2026] [security2:error] [pid 6487:tid 6487] [client 160.25.5.253:59754] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zost.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zost.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiIEsjoTQGWNkqfz-nArZQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 21:16:02
(3 days ago)
[04/Jun/2026:21:16:01 +0000] host=lovelyrender.app server=lovelyrender.app ip=160.25.5.253 method=PO ...
show more
[04/Jun/2026:21:16:01 +0000] host=lovelyrender.app server=lovelyrender.app ip=160.25.5.253 method=POST req=/xmlrpc.php uri=/index.php status=302 bytes=0 rt=0.057 urt=0.057 ref="-" ua="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
๐ฒ๐ฝ
octageeks.com
2026-06-04 04:09:57
(4 days ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐ฉ๐ช
Martin Lundstrom
2026-06-03 13:04:47
(4 days ago)
https://www.eagleeye-intelligence.com โ WordPress attack. Automatically detected and blocked.
Web App Attack
๐ฌ๐ง
spamverify.com
2026-05-25 22:47:06
(1 week ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-05-15 16:48:41
(3 weeks ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐บ๐ธ
mnsf
2026-03-06 11:05:22
(3 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ซ๐ท
Baking333
2026-03-06 10:40:59
(3 months ago)
[redacted] 160.25.5.253 - - [06/Mar/2026:11:40:58 +0100] "GET /api/.env HTTP/1.1" 302 5284 0/38760 " ...
show more
[redacted] 160.25.5.253 - - [06/Mar/2026:11:40:58 +0100] "GET /api/.env HTTP/1.1" 302 5284 0/38760 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" [redacted] 160.25.5.253 - - [06/Mar/2026:11:40:58 +0100] "GET /api/.[redacted] HTTP/1.1" 302 5284 0/39487 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-03-06 10:31:35
(3 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ซ๐ท
masterguru
2026-03-06 09:31:05
(3 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-03-06 09:14:31
(3 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack