🇩🇪
FeG Deutschland
2026-09-13 05:57:36
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇦🇺
oncord
2026-09-10 08:37:56
(2 days ago)
Form spam
Web Spam
Anonymous
2026-09-08 10:31:45
(4 days ago)
Web application attack detected.
Web App Attack
🇬🇧
oncord
2026-08-31 09:54:51
(1 week ago)
Form spam
Web Spam
🇦🇺
oncord
2026-08-29 22:12:57
(2 weeks ago)
Form spam
Web Spam
🇨🇿
ptlab
2026-07-23 12:46:09
(1 month ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
🇩🇪
LRob
2026-07-05 00:45:26
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-02 06:41:43
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 02:41:36.038761 2026] [security2:error] [pid 17680:tid 17680] [client 167.253.19.245:57807] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akYIIOTGvQ5Y7Psq3DHrGgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
JimArchon72
2026-06-24 18:05:01
(2 months ago)
2026/06/24 18:02:58 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
🇺🇸
mnsf
2026-06-19 17:06:52
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-14 19:00:45
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 15:00:40.308711 2026] [security2:error] [pid 2547:tid 2547] [client 167.253.19.245:61529] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nutandboltguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nutandboltguy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai76WGvNqmECSluYjIR8tQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-11 04:37:20
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 00:37:15.574948 2026] [security2:error] [pid 27513:tid 27513] [client 167.253.19.245:51847] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||femdomchatbot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "femdomchatbot.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aio7ewgS-xQIXRXOZcXA6AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-26 11:20:42
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 07:20:38.065017 2026] [security2:error] [pid 16451:tid 16463] [client 167.253.19.245:9823] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adultbaja.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adultbaja.com"] [uri "/2024.sql"] [unique_id "ahWCBsPyXPUiFz8R6K5C7AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-22 12:45:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 08:45:30.646050 2026] [security2:error] [pid 17780:tid 17780] [client 167.253.19.245:48543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desertautoworks.com"] [uri "/wp-config.php.dist"] [unique_id "ahBP6k_xc1f6QDSEsvZ6pwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 16:07:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 167.253.19.245 (167-253-19-245.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:07:28.955863 2026] [security2:error] [pid 16817:tid 16817] [client 167.253.19.245:58073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulsingdahlsen.com"] [uri "/wp-config.php.save"] [unique_id "ag3cQCKnzt0TJ4EWozZEjAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack