๐ฉ๐ช
ghostwarriors
2026-05-12 09:52:21
(3 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-05-06 14:20:39
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 02:33:30
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 167.253.48.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 167.253.48.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 22:33:23.473399 2026] [security2:error] [pid 16801:tid 16801] [client 167.253.48.254:19651] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hischurchatwork.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hischurchatwork.org"] [uri "/wp-json/wp/v2/users"] [unique_id "afAcc9bpwcyjtg0NmVv6XgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 14:00:41
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 167.253.48.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 167.253.48.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 10:00:33.562983 2026] [security2:error] [pid 17288:tid 17288] [client 167.253.48.254:10107] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gasoilliquidsdaily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gasoilliquidsdaily.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae9sATOPVAwifFcPXTQfYwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-27 10:04:55
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
www.winos.me
2026-03-08 23:51:06
(2 months ago)
Banned due to high error rate on HTTP/1.1 protocol
Brute-Force
Web App Attack
๐ง๐ช
voormedia
2026-02-27 06:00:49
(3 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ซ๐ท
tilellit.pro
2026-02-05 12:57:24
(4 months ago)
Fail2Ban banned 167.253.48.254 for security violations in jail wp-armour. Log: 2026/02/05 12:57:24 [ ...
show more
Fail2Ban banned 167.253.48.254 for security violations in jail wp-armour. Log: 2026/02/05 12:57:24 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 167.253.48.254 | Target: wplogin" , client: 167.253.48.254, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฑ๐ป
garmtech.com
2026-01-25 09:25:20
(4 months ago)
IM360 WAF: Attempt to upload malware
Hacking
๐ฑ๐ป
garmtech.com
2026-01-02 09:00:29
(5 months ago)
IM360 WAF: Attempt to upload malware
Hacking
๐ง๐ช
voormedia
2025-12-29 13:11:18
(5 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐ฌ๐ง
Bytemark
2025-12-27 19:16:36
(5 months ago)
167.253.48.254 - - [27/Dec/2025:19:16:32 +0000] "GET /wp-login.php HTTP/1.1" 404 47 "https://www.goo ...
show more
167.253.48.254 - - [27/Dec/2025:19:16:32 +0000] "GET /wp-login.php HTTP/1.1" 404 47 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
167.253.48.254 - - [27/Dec/2025:19:16:34 +0000] "GET /wp-login.php HTTP/1.1" 404 47 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
167.253.48.254 - - [27/Dec/2025:19:16:35 +0000] "GET /wp-login.php HTTP/1.1" 404 47 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-12-27 13:12:39
(5 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User A ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User Agent: N/A - Timestamp: 12/27/2025 1:12 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-12-26 01:54:21
(5 months ago)
WP Login Scan Activities
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-12-25 23:36:26
(5 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User A ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User Agent: N/A - Timestamp: 12/25/2025 11:36 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack