๐ฒ๐ฝ
octageeks.com
2026-09-21 04:08:09
(2 days ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 16:54:51
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 12:54:43.884714 2026] [security2:error] [pid 14715:tid 14715] [client 165.22.38.161:54978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lenorasflowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lenorasflowers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arAP0xwLNKipvlMoK5IvqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 15:24:25
(2 days ago)
165.22.38.161 - - [20/Sep/2026:15:23:32 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 ( ...
show more
165.22.38.161 - - [20/Sep/2026:15:23:32 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0" "-" edge="165.22.38.161"
165.22.38.161 - - [20/Sep/2026:15:23:33 +0000] "GET /?author=3 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0" "-" edge="165.22.38.161"
165.22.38.161 - - [20/Sep/2026:15:23:37 +0000] "GET /?author=4 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" edge="165.22.38.161"
165.22.38.161 - - [20/Sep/2026:15:23:39 +0000] "GET /?author=5 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "-" edge="165.22.38.161"
165.22.38.161 - - [20/Sep/2026:15:23:41 +0000] "GET /?author=6 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "-" edge="165.22.38.161"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 06:23:10
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 02:23:05.572039 2026] [security2:error] [pid 16269:tid 16269] [client 165.22.38.161:37362] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dvdmasters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dvdmasters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq97ydxKn42SK8W59YWk7wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-19 23:12:14
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 22:41:21
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 18:41:17.467521 2026] [security2:error] [pid 15759:tid 15759] [client 165.22.38.161:53830] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adlc18.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adlc18.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8PjQPIgRflGB3aREJyigAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 20:12:07
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 16:12:02.577796 2026] [security2:error] [pid 12284:tid 12284] [client 165.22.38.161:42938] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.surviquo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.surviquo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7sktbaIQxTokPjzHVLMQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 17:29:33
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:29:29.002349 2026] [security2:error] [pid 32292:tid 32292] [client 165.22.38.161:46630] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7GeAnivgYRYGBS4-g_qAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 12:52:29
(3 days ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 12:26:47
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:26:44.679847 2026] [security2:error] [pid 13958:tid 13958] [client 165.22.38.161:36502] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tristarus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tristarus.com"] [uri "/wordpress/wp-json/wp/v2/users"] [unique_id "aq5_hCwRUhS5vrXyb5bPRgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:19:28
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.38.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:19:20.735719 2026] [security2:error] [pid 28335:tid 28335] [client 165.22.38.161:58800] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||smoothiessoupssalads.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "smoothiessoupssalads.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5vuBxOU1lG_J1Dyd0JAQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-19 10:23:53
(4 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 165.22.38.161 (US/United States/-): 1 in the l ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 165.22.38.161 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 165.22.38.161 - - [19/Sep/2026:12:23:47 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12038 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0" "-" host=studioegizi.it
show less
Port Scan
๐ซ๐ฎ
YF
2026-09-18 16:00:36
(4 days ago)
WordPress author enumeration
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-17 22:58:36
(5 days ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 165.22.38.161 (US/United States/-)
Brute-Force
๐บ๐ธ
mnsf
2026-09-17 12:05:07
(5 days ago)
Too many Status 40X (11)
Brute-Force
Web App Attack