๐ณ๐ฑ
Savvii
2026-08-31 06:34:39
(5 hours ago)
20 attempts against mh-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 22:07:28
(3 days ago)
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-16 16:02:48
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 170.168.30.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 170.168.30.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 12:02:38.905249 2026] [security2:error] [pid 9226:tid 9236] [client 170.168.30.104:61931] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aafm.org|F|2"] [data ".gafm.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aafm.org"] [uri "/www.GAFM.com"] [unique_id "aoHfHpXb7YqXDg6p_uMFbgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
zam
2026-07-26 17:14:51
(1 month ago)
170.168.30.104 - - [26/Jul/2026:17:14:49 +0000] "POST /xmlrpc.php HTTP/1.1" 403 239
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-18 05:12:44
(1 month ago)
HTTP flood against /retreat-corp on Apache webserver
Brute-Force
๐บ๐ธ
nyt
2026-07-17 22:20:33
(1 month ago)
WP User Enumeration, WP Author Enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 20:42:09
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 170.168.30.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.30.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 16:42:04.368271 2026] [security2:error] [pid 20317:tid 20317] [client 170.168.30.104:30669] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||numeralla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "numeralla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "allCHFZFDNJNmAnBf10zsQAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-15 10:42:08
(1 month ago)
block ruleset 486D2EE5E731CC049D1E480D68D04DFFE28AADF1
Bad Web Bot
๐ง๐ช
Saec
2026-06-05 18:00:25
(2 months ago)
Jarvis auto-ban: CF honeypot path /wp-login.php (2ร on saec.me)
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:56:24
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.30.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.30.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:56:17.155906 2026] [security2:error] [pid 15365:tid 15365] [client 170.168.30.104:57535] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cormanleigh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cormanleigh.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab36wY1biDB2A45WV5_z0wAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-17 13:56:54
(5 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฉ๐ช
kjaerulff
2026-03-11 14:37:21
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐ซ๐ท
masterguru
2026-02-19 07:37:39
(6 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 170.168.30.104 (NL/The Netherlands/-): 1 in th ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 170.168.30.104 (NL/The Netherlands/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-03 08:07:19
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.30.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.30.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 03:07:16.230670 2026] [security2:error] [pid 4282:tid 4296] [client 170.168.30.104:17741] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chadzone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chadzone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYGstAc05TEOxaibHOVMBwAAAEw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-30 12:26:14
(7 months ago)
Multiple web server 400 error codes from same source ip
Web App Attack