🇩🇪
FeG Deutschland
2026-09-15 15:08:03
(56 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
🇩🇪
LRob
2026-09-15 11:15:43
(4 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /license.txt | ua: python-reque ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /license.txt | ua: python-requests/2.27.1 | 2026-09-15 11:15 UTC
show less
Port Scan
Web App Attack
🇺🇸
mnsf
2026-09-15 06:05:30
(9 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-15 05:49:03
(10 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /license.txt | 2026-09-15 05:49 UTC
show less
Bad Web Bot
🇩🇪
BlueWire Hosting
2026-09-15 05:13:25
(10 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-15 04:09:46
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 178.128.20.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 178.128.20.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:09:37.710243 2026] [security2:error] [pid 1981:tid 1981] [client 178.128.20.120:55684] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "aqjFAZhxG0Fn8EvsgE2xAQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-15 04:06:02
(11 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-15 01:11:10
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.128.20.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.128.20.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:11:03.693848 2026] [security2:error] [pid 5228:tid 5228] [client 178.128.20.120:50993] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kaldaragroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kaldaragroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqibJwKyt1qAhVC1penpAQAAAAc"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-15 00:15:31
(15 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: status.definitelynotahoneypot.top | URI: /wp-login.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 23:31:26
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.128.20.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.128.20.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:31:21.834809 2026] [security2:error] [pid 29567:tid 29567] [client 178.128.20.120:62469] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stellabluesales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stellabluesales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqiDya94uxaQnai-kE_jGgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-14 23:20:02
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-admin-interface-probing
Web App Attack
Hacking
🇫🇷
ELYAZ
2026-09-14 23:15:42
(16 hours ago)
(y3) Failed access -byebye- from 178.128.20.120 (SG/Singapore/-): (CF_ENABLE)
Hacking
🇳🇱
Site.eu
2026-09-14 22:11:12
(17 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-14 21:54:18
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.128.20.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.128.20.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:54:10.909157 2026] [security2:error] [pid 26327:tid 26327] [client 178.128.20.120:57351] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dd214chronicle.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dd214chronicle.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqhtAo1pkM3U2-s_Q3KhqQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-14 21:40:05
(18 hours ago)
Bad behaviour
Web Spam