🇩🇪
pltcldvlpr
2026-09-03 03:04:36
(4 days ago)
CMS/framework probe: 170.168.99.233 - - [03/Sep/2026:05:04:35 +0200] "GET /wp-json/ HTTP/1.1" 404 16 ...
show more
CMS/framework probe: 170.168.99.233 - - [03/Sep/2026:05:04:35 +0200] "GET /wp-json/ HTTP/1.1" 404 162 "-" "curl/8.14.1" asn=59651 org="Alex Largman" country=DE
...
show less
Web App Attack
🇺🇸
Hazael
2026-09-02 20:58:53
(4 days ago)
SNOOPING - intended to probe for or exploit website vulnerabilities. From: Kropp, Allemagne - Alex L ...
show more
SNOOPING - intended to probe for or exploit website vulnerabilities. From: Kropp, Allemagne - Alex Largman (AS59651 AS QualityNetwork) - Agent: curl/8.14.1
show less
Web App Attack
Anonymous
2026-08-29 15:54:35
(1 week ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
Anonymous
2026-08-23 23:16:04
(2 weeks ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-01 13:23:40
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 170.168.99.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.99.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:23:35.884878 2026] [security2:error] [pid 2266254:tid 2266254] [client 170.168.99.233:19969] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||unified-dispatch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "unified-dispatch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "am3zVzuTsHe1A-6DMPiLNAAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-29 09:57:16
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 170.168.99.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.99.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 05:57:11.637946 2026] [security2:error] [pid 21753:tid 21753] [client 170.168.99.233:60219] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||manb.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "manb.org"] [uri "/wp-json/wp/v2/users"] [unique_id "amnOdzplS4Gk6e2z98uMQgAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-07-29 06:20:08
(1 month ago)
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:0
Hacking
🇨🇦
DRI
2026-07-17 22:33:24
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
🇪🇸
librebit
2026-07-10 01:54:58
(1 month ago)
Brute force
Brute-Force
🇪🇸
librebit
2026-07-04 06:52:17
(2 months ago)
Brute force
Brute-Force
🇪🇸
librebit
2026-07-01 01:16:51
(2 months ago)
Brute force
Brute-Force
🇩🇪
kjaerulff
2026-04-12 20:35:10
(4 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
🇺🇸
TPI-Abuse
2026-04-10 05:35:19
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.99.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.99.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 01:35:16.006436 2026] [security2:error] [pid 1654132:tid 1654132] [client 170.168.99.233:41269] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yubagals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yubagals.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adiMFMXD5RxKx1DSUaCcCAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-04-09 20:21:00
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-30 00:31:32
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.99.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.99.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 20:31:25.826016 2026] [security2:error] [pid 6373:tid 6373] [client 170.168.99.233:55291] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||antcanada.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "antcanada.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acnEXYc06DSQ2v27Y6d58gAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack