๐ต๐ฑ
mscode.pl
2026-09-30 08:02:32
(11 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC)
Protocol: HTTP/1.1 (GET method)
Zone: r2-dev.selify.io
Endpoint: /license.txt
UA: python-requests/2.27.1
show less
Bad Web Bot
๐จ๐ญ
backslash
2026-09-30 07:51:00
(11 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ฉ๐ช
neckaralb-admin.de
2026-09-30 06:01:51
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-30 05:48:46
(13 hours ago)
stkildashule.org.au:443 178.128.89.80 - - [30/Sep/2026:15:48:43 +1000] "GET /?author=1 HTTP/1.1" 404 ...
show more
stkildashule.org.au:443 178.128.89.80 - - [30/Sep/2026:15:48:43 +1000] "GET /?author=1 HTTP/1.1" 404 53792 "https://wordpress.org/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ฎ
YF
2026-09-30 04:30:35
(15 hours ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ณ๐ฑ
MacLotsen
2026-09-30 02:00:57
(17 hours ago)
178.128.89.80 - - [30/Sep/2026:03:58:56 +0200] "POST /wp-login.php HTTP/1.1" 200 4416 "https://www.a ...
show more
178.128.89.80 - - [30/Sep/2026:03:58:56 +0200] "POST /wp-login.php HTTP/1.1" 200 4416 "https://www.afkewiersma.nl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:121.0) Gecko/20100101 Firefox/121.0"
178.128.89.80 - - [30/Sep/2026:03:59:07 +0200] "POST /wp-login.php HTTP/1.1" 200 4415 "https://www.afkewiersma.nl/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
178.128.89.80 - - [30/Sep/2026:03:59:16 +0200] "POST /wp-login.php HTTP/1.1" 200 4416 "https://www.afkewiersma.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
178.128.89.80 - - [30/Sep/2026:03:59:27 +0200] "POST /wp-login.php HTTP/1.1" 200 4414 "https://www.afkewiersma.nl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
178.128.89.80 - - [30/Sep/2026:03:59:52 +0200] "POST /w
...
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 00:01:44
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.128.89.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 178.128.89.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:01:40.612020 2026] [security2:error] [pid 17619:tid 17619] [client 178.128.89.80:51356] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tckgbookkeeping.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tckgbookkeeping.biz"] [uri "/wp-json/wp/v2/users"] [unique_id "arxRZF_tus2rBxx3nz5qHwAAAAk"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:27:24
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.128.89.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 178.128.89.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:27:19.671198 2026] [security2:error] [pid 25452:tid 25452] [client 178.128.89.80:54143] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.chaire-construction-4-0.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.chaire-construction-4-0.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arw7R_t0SfduxuHsiWK4tgAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:27:50
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 178.128.89.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 178.128.89.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:27:47.274722 2026] [security2:error] [pid 23807:tid 23807] [client 178.128.89.80:64562] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.emsystemsltd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.emsystemsltd.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arwRM6D1kUOU3bRPyiIXmQAAAC4"], referer: https://duckduckgo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-29 19:25:13
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-09-29 16:57:02
(1 day ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-09-29 16:04:32
(1 day ago)
27.604 requests from untrusted country (1w6d19h)
Brute-Force
Bad Web Bot
๐ฉ๐ช
LRob
2026-09-29 15:43:15
(1 day ago)
Not following 301 redirects โ wasted requests | method: GET | path: /wp-login.php | ua: Mozilla/5.0 ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: /wp-login.php | ua: Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 | 2026-09-29 15:43 UTC
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-09-29 07:22:36
(1 day ago)
Not following 301 redirects โ wasted requests | method: GET | path: /license.txt | ua: python-reques ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: /license.txt | ua: python-requests/2.27.1
show less
Bad Web Bot