๐ฒ๐ฝ
octageeks.com
2026-07-22 04:17:41
(8 hours ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 21:58:33
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 17:58:24.683855 2026] [security2:error] [pid 25289:tid 25289] [client 185.104.44.149:11612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||matt-bechtel.neconebooks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "matt-bechtel.neconebooks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al_rgIYDO8HB0ZnL9JUXTQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 21:15:16
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 17:15:09.013176 2026] [security2:error] [pid 855195:tid 855195] [client 185.104.44.149:19004] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realclean.net"] [uri "/wp-json/wp/v2/users"] [unique_id "al_hXXgaNb6bVgeyR7UgvQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:27:25
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:27:16.642784 2026] [security2:error] [pid 12918:tid 12918] [client 185.104.44.149:44142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||visionremota.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "visionremota.info"] [uri "/wp-json/wp/v2/users"] [unique_id "al_WJIQpFBeMZZf8nGWmVQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-21 20:05:17
(16 hours ago)
Abuse Detected (13)
Brute-Force
Web App Attack
๐บ๐ธ
xxkodedxx
2026-07-21 19:31:59
(17 hours ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: UA / AS200000 Hosting Ukraine LTD
Active: 19:31:44 UTC
Volume: 1 HTTP req
Probed: /?author=4&feed=rss2
Status mix: 444ร1
Vhost fishing: cards.zvxlabs.com
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 19:31:10
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 15:31:02.089846 2026] [security2:error] [pid 1056168:tid 1056168] [client 185.104.44.149:48538] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mikedeutsch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mikedeutsch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al_I9h-nMtc7WrWCCP-CGgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 19:14:35
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 15:14:30.234162 2026] [security2:error] [pid 13338:tid 13338] [client 185.104.44.149:63574] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||crep-psych.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "crep-psych.org"] [uri "/wp-json/wp/v2/users"] [unique_id "al_FFmMwAgqFv0FypiL99wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:24:32
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:24:25.692115 2026] [security2:error] [pid 254687:tid 254687] [client 185.104.44.149:42168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lenorasflowers.lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lenorasflowers.lahamradio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al-5WQ66bdzGSenlHZpN6wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:06:37
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:06:31.252742 2026] [security2:error] [pid 13689:tid 13689] [client 185.104.44.149:20070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thereisaplaceonearth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thereisaplaceonearth.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "al-1JxeZ8QC8SR5nIU111QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-21 17:58:16
(18 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-21 17:32:33
(19 hours ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 15:14:09
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 11:14:01.745273 2026] [security2:error] [pid 4537:tid 4537] [client 185.104.44.149:53892] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||imbrasacademic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "imbrasacademic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al-MuTYuM1weaql6X8g4BgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 14:55:03
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.149 (business-58.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 10:54:55.653244 2026] [security2:error] [pid 5329:tid 5329] [client 185.104.44.149:56154] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nextlevelcharge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nextlevelcharge.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "al-IP-7FClky8afX4f5SBgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack