🇪🇸
librebit
2026-09-12 10:04:22
(15 hours ago)
Brute force
Brute-Force
🇨🇿
Countryman
2026-09-12 00:10:01
(1 day ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇸🇪
OnTheEdge
2026-08-11 09:35:36
(1 month ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇩🇪
C C
2026-08-06 10:37:29
(1 month ago)
Distributed scraping attack: 3436 req from 3224 rotating proxy IPs, waves of up to 156 req in 138s o ...
show more
Distributed scraping attack: 3436 req from 3224 rotating proxy IPs, waves of up to 156 req in 138s on a single URL | this IP: 1 req, 1 blocked
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-16 08:03:08
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 04:03:02.464043 2026] [security2:error] [pid 18255:tid 18255] [client 170.168.242.155:58007] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||starrmail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "starrmail.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajEDNi2wInj76on2poa82wAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-06-14 17:03:27
(2 months ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-06-13 09:54:26
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 05:54:20.972467 2026] [security2:error] [pid 16157:tid 16157] [client 170.168.242.155:17729] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||teenybikini.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "teenybikini.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai0ozGz1F2mVHSzn7weC1gAAACM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-11 19:36:56
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 15:36:51.909552 2026] [security2:error] [pid 21456:tid 21474] [client 170.168.242.155:33955] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mjkotob.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mjkotob.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aisOU-rWl-_jWzxt9vLpvgAAARA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-10 20:37:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:37:28.495733 2026] [security2:error] [pid 9668:tid 9668] [client 170.168.242.155:63733] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.csm-dtc.com"] [uri "/wp-config.php.bck"] [unique_id "ainLCLraPL3cxH7iSeucvQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-22 11:43:46
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 07:43:39.283565 2026] [security2:error] [pid 17644:tid 17644] [client 170.168.242.155:52423] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stormwlf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stormwlf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahBBa4Vtz9W5JGmhiJw3ZgAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-21 11:51:38
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 07:51:30.705530 2026] [security2:error] [pid 24394:tid 24394] [client 170.168.242.155:63419] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||harwoodmechanical.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "harwoodmechanical.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag7xwhRWPm_mu8KH3HaHFAAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-05-18 19:04:59
(3 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
🇺🇸
octageeks.com
2026-05-18 04:06:30
(3 months ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
Anonymous
2026-05-17 10:24:38
(3 months ago)
2026-05-17T12:24:37.570728+02:00 aion wordpress[395390]: Blocked authentication attempt for admin fr ...
show more
2026-05-17T12:24:37.570728+02:00 aion wordpress[395390]: Blocked authentication attempt for admin from 170.168.242.155
...
show less
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2026-05-15 09:49:55
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:49:47.909708 2026] [security2:error] [pid 13592:tid 13640] [client 170.168.242.155:56489] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kincers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kincers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agbsO7bybig9o9uDs-oOcwAAAE0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack