๐บ๐ธ
cwytech
2026-09-21 19:49:28
(5 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 15:50:25
(2 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐ซ๐ท
masterguru
2026-09-19 10:26:39
(2 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐ฉ๐ช
LRob
2026-09-18 00:33:15
(4 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-18 00:33 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 00:18:28
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 169.58.232.171 (servaspace.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 169.58.232.171 (servaspace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 20:18:21.522401 2026] [security2:error] [pid 18900:tid 18900] [client 169.58.232.171:40864] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wildlandconservancy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wildlandconservancy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqyDTTGOSmIILq6akEgbtAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 13:21:26
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 169.58.232.171 (servaspace.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 169.58.232.171 (servaspace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:21:22.974815 2026] [security2:error] [pid 4124:tid 4124] [client 169.58.232.171:45182] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lyldevelopers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lyldevelopers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqvpUrxLnOOrwMMdjvR9JAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-17 13:18:46
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 07:59:40
(4 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-17 07:59 UTC
show less
Bad Web Bot
๐ฉ๐ช
filstal.org
2026-09-17 07:59:09
(4 days ago)
WordPress user enumeration attempt detected.
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-17 07:06:28
(4 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 06:10:39
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 169.58.232.171 (servaspace.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 169.58.232.171 (servaspace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:10:34.669914 2026] [security2:error] [pid 29840:tid 29840] [client 169.58.232.171:34142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.orcastrong.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.orcastrong.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aquEWruYjg0JRJYfwSQCjgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-17 05:54:11
(4 days ago)
169.58.232.171 - - [17/Sep/2026:05:53:28 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 ...
show more
169.58.232.171 - - [17/Sep/2026:05:53:28 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0" "-" edge="169.58.232.171"
169.58.232.171 - - [17/Sep/2026:05:53:42 +0000] "GET /?author=3 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0" "-" edge="169.58.232.171"
169.58.232.171 - - [17/Sep/2026:05:53:47 +0000] "GET /?author=4 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:51.0) Gecko/20100101 Firefox/51.0" "-" edge="169.58.232.171"
169.58.232.171 - - [17/Sep/2026:05:53:55 +0000] "GET /?author=5 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" edge="169.58.232.171"
169.58.232.171 - - [17/Sep/2026:05:54:07 +0000] "GET /?author=6 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0" "-" edge="169.58.232.171"
...
show less
Web App Attack
๐ซ๐ฎ
stinpriza
2026-09-17 03:24:23
(4 days ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
๐ง๐ท
Sipo Chutรฃo
2026-09-09 03:00:01
(1 week ago)
/xmlrpc.php
Hacking
Anonymous
2026-09-02 13:49:46
(2 weeks ago)
169.58.232.171 - - [02/Sep/2026:21:49:45 +0800] "POST /en/xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5 ...
show more
169.58.232.171 - - [02/Sep/2026:21:49:45 +0800] "POST /en/xmlrpc.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0"
...
show less
Bad Web Bot
Web App Attack