๐ช๐ธ
librebit
2026-06-13 06:51:30
(2 days ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-06-11 19:13:39
(3 days ago)
RDWeb scan
Web App Attack
๐บ๐ธ
JustMeHere
2026-04-27 23:02:27
(1 month ago)
[Mon Apr 27 19:02:23.101852 2026] [security2:error] [pid 190311:tid 190451] [client 170.168.96.212:6 ...
show more
[Mon Apr 27 19:02:23.101852 2026] [security2:error] [pid 190311:tid 190451] [client 170.168.96.212:65061] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/xmlrpc.php"] [unique_id "ae_q_wZhKrqtHg6-LTLw8gAAAIk"]
...
show less
Web App Attack
Anonymous
2026-04-27 08:50:57
(1 month ago)
FPROCO WEBEXPLOIT 170.168.96.212 (170.168.96.212)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-24 08:47:31
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 170.168.96.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.96.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 24 04:47:27.394458 2026] [security2:error] [pid 4493:tid 4493] [client 170.168.96.212:35621] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rahmanou.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rahmanou.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aesuH8SCDy6mu5ZHZdfItAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-04-20 22:45:50
(1 month ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-04-17 12:06:09
(1 month ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-12 06:30:18
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.96.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.96.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 02:30:13.065358 2026] [security2:error] [pid 2515507:tid 2515507] [client 170.168.96.212:40901] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||joycebrown.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "joycebrown.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ads79cYsAzMNPkQVmZG1NwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-03-30 05:34:31
(2 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-02-24 21:45:14
(3 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-01-20 12:27:23
(4 months ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 170.168.96.212 (PL/Poland/-): 1 in the last 3 ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 170.168.96.212 (PL/Poland/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-31 11:10:57
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.96.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.96.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 06:10:50.570912 2025] [security2:error] [pid 18849:tid 18849] [client 170.168.96.212:43281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wealthsec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wealthsec.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aVUEus49SZzmYdXHU-D2JAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-27 20:39:33
(5 months ago)
wordpress-trap
Web App Attack