πΊπΈ
TPI-Abuse
2026-06-01 21:14:43
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.i ...
show more
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 17:14:40.663794 2026] [security2:error] [pid 24402:tid 24407] [client 185.167.90.252:49388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||seriousgames-system.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "seriousgames-system.info"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah32QEzxaA_bqEbLTie3FwAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-06-01 21:09:23
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
mind5t0rm
2026-06-01 21:09:10
(2 days ago)
(WPLOGIN) WP Login Attack 185.167.90.252 (ES/Spain/252-90.dimatica.es.90.167.185.in-addr.arpa): 3 in ...
show more
(WPLOGIN) WP Login Attack 185.167.90.252 (ES/Spain/252-90.dimatica.es.90.167.185.in-addr.arpa): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 185.167.90.252 - - [02/Jun/2026:03:48:40 +0700] "GET /wp-login.php HTTP/2.0" 200 3126 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
185.167.90.252 - - [02/Jun/2026:03:48:42 +0700] "POST /wp-login.php HTTP/2.0" 200 4166 "https://thevasilis.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
185.167.90.252 - - [02/Jun/2026:04:09:07 +0700] "GET /wp-login.php HTTP/2.0" 200 2816 "-" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-06-01 20:36:04
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.i ...
show more
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 16:35:58.826739 2026] [security2:error] [pid 3061:tid 3061] [client 185.167.90.252:32944] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wild-goose.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wild-goose.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ah3tLkGTFsxt_MljAe9grAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-01 20:20:04
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.i ...
show more
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 16:19:57.159956 2026] [security2:error] [pid 32194:tid 32194] [client 185.167.90.252:43500] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ritterlien.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ritterlien.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah3pbUz5IsGg3UCmZ2K8xAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
integrantservices.com
2026-06-01 19:41:04
(2 days ago)
(PERMBLOCK) 185.167.90.252 (ES/Spain/252-90.dimatica.es.90.167.185.in-addr.arpa) has had more than 4 ...
show more
(PERMBLOCK) 185.167.90.252 (ES/Spain/252-90.dimatica.es.90.167.185.in-addr.arpa) has had more than 4 temp blocks
show less
Hacking
πΊπΈ
TAY
2026-06-01 19:40:14
(2 days ago)
185.167.90.252 - - [02/Jun/2026:03:34:59 +0800] "POST /wp-login.php HTTP/1.1" 200 2676 "https://litt ...
show more
185.167.90.252 - - [02/Jun/2026:03:34:59 +0800] "POST /wp-login.php HTTP/1.1" 200 2676 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
185.167.90.252 - - [02/Jun/2026:03:39:39 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
185.167.90.252 - - [02/Jun/2026:03:40:13 +0800] "POST /wp-login.php HTTP/1.1" 200 2676 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-01 19:17:24
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.i ...
show more
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 15:17:16.459428 2026] [security2:error] [pid 31513:tid 31530] [client 185.167.90.252:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mindgardens.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mindgardens.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah3avICwP9-QU_blC760KwAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
BRHosting
2026-06-01 19:16:02
(2 days ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
π¨π¦
polycoda
2026-06-01 19:12:37
(2 days ago)
π Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack
π¨π¦
KIsmay
2026-06-01 19:10:56
(2 days ago)
Jun 1 11:20:19 www4 WPAudit[279638]: 185.167.90.252 lemoncreekcampground.ca "Mozilla/5.0 (Windows N ...
show more
Jun 1 11:20:19 www4 WPAudit[279638]: 185.167.90.252 lemoncreekcampground.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" sbd-admin:test1234 FAIL
Jun 1 12:05:01 www4 WPAudit[266623]: 185.167.90.252 www.valhallasafety.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" sbd-admin:sbd-admin123@@ FAIL
Jun 1 13:03:28 www4 WPAudit[287778]: 185.167.90.252 imaginesalmon.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" se7enoaks:@se7enoaks!23# FAIL
Jun 1 15:00:19 www4 WPAudit[296498]: 185.167.90.252 www.siscobc.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:Sbdadmin88 FAIL
Jun 1 15:10:56 www4 WPAudit[296498]: 185.167.90.252 siscobc.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537
...
show less
Brute-Force
Web App Attack
π©πͺ
ger-stg-sifi1
2026-06-01 18:40:59
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-01 18:40:34
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.i ...
show more
(mod_security) mod_security (id:225170) triggered by 185.167.90.252 (252-90.dimatica.es.90.167.185.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 14:40:29.584073 2026] [security2:error] [pid 13915:tid 13915] [client 185.167.90.252:42288] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bostonlog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bostonlog.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah3SHUctAmR3C4LHkCwckwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-06-01 18:40:33
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
π©πͺ
DocNetzwerk
2026-06-01 18:18:48
(2 days ago)
(wordpress) Failed wordpress login from 185.167.90.252 (ES/Spain/252-90.dimatica.es.90.167.185.in-ad ...
show more
(wordpress) Failed wordpress login from 185.167.90.252 (ES/Spain/252-90.dimatica.es.90.167.185.in-addr.arpa)
show less
Brute-Force