๐ฉ๐ช
Jochen Pretli
2026-10-09 00:08:33
(1 day ago)
connection to honeypot
Email Spam
Port Scan
๐ซ๐ท
sthoyer.de
2026-10-08 23:46:46
(1 day ago)
Oct 9 01:46:45 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
Oct 9 01:46:45 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=165.227.211.231 DST=173.212.223.67 LEN=44 TOS=0x00 PREC=0x00 TTL=244 ID=250 PROTO=TCP SPT=61009 DPT=3306 WINDOW=1025 RES=0x00 SYN URGP=0
...
show less
Port Scan
Anonymous
2026-10-07 04:55:25
(3 days ago)
denied traffic to a honeypot network. destination port 8808.
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2025-10-15 18:55:54
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 165.227.211.231 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 165.227.211.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 15 14:55:51.130183 2025] [security2:error] [pid 8099:tid 8099] [client 165.227.211.231:53932] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.manosentuayuda.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.manosentuayuda.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aO_uN8aOJwBk9a6UUpcRxwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-15 12:54:57
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 165.227.211.231 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 165.227.211.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 15 08:54:50.315716 2025] [security2:error] [pid 28287:tid 28287] [client 165.227.211.231:61505] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||papelandia.com.ve|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "papelandia.com.ve"] [uri "/wp-json/wp/v2/users/"] [unique_id "aO-Zmr7avdPwlhdFG1uFZAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2025-10-15 12:41:34
(11 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
gu-alvareza
2025-10-15 07:05:04
(11 months ago)
WordPress.REST.API.Username.Enumeration.Information.Disclosure
Web App Attack
๐ธ๐ฌ
pusathosting.com
2025-10-14 19:50:05
(11 months ago)
24ds22 bruteforce
Brute-Force
Web App Attack
๐ธ๐ฌ
pusathosting.com
2025-10-14 19:30:04
(11 months ago)
2ds22 bruteforce
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-14 18:31:22
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 165.227.211.231 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 165.227.211.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 14 14:31:17.613227 2025] [security2:error] [pid 22014:tid 22031] [client 165.227.211.231:55871] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.killasgarage.bike|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.killasgarage.bike"] [uri "/wp-json/wp/v2/users/"] [unique_id "aO6W9afvrWgRiI1doVXgHwAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-10-14 18:20:53
(11 months ago)
165.227.211.231 - - [14/Oct/2025:21:20:52 +0300] "GET /xmlrpc.php?rsd HTTP/1.1" 404 196 "-" "Mozilla ...
show more
165.227.211.231 - - [14/Oct/2025:21:20:52 +0300] "GET /xmlrpc.php?rsd HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
165.227.211.231 - - [14/Oct/2025:21:20:52 +0300] "GET /xmlrpc.php?rsd HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
...
show less
Web App Attack
Anonymous
2025-10-14 16:54:32
(11 months ago)
wordpress exploit scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-14 16:40:14
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 165.227.211.231 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 165.227.211.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 14 12:40:07.276537 2025] [security2:error] [pid 9402:tid 9402] [client 165.227.211.231:58082] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fundaciondamashcc.org.ec|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fundaciondamashcc.org.ec"] [uri "/wp-json/wp/v2/users/"] [unique_id "aO5857ndYMo_3Y5_NnsrYwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2025-10-14 16:14:17
(11 months ago)
Attack against Apache (too many 404s)
Web App Attack