๐ซ๐ท
masterguru
2026-09-20 09:50:46
(6 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐ช๐ธ
robotstxt
2026-09-20 07:33:01
(8 hours ago)
185.245.183.110 - - [20/Sep/2026:07:32:08 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 ...
show more
185.245.183.110 - - [20/Sep/2026:07:32:08 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0" "-" edge="185.245.183.110"
185.245.183.110 - - [20/Sep/2026:07:32:10 +0000] "GET /?author=3 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:41.0) Gecko/20100101 Firefox/41.0" "-" edge="185.245.183.110"
185.245.183.110 - - [20/Sep/2026:07:32:12 +0000] "GET /?author=4 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:86.0) Gecko/20100101 Firefox/86.0" "-" edge="185.245.183.110"
185.245.183.110 - - [20/Sep/2026:07:32:15 +0000] "GET /?author=5 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0" "-" edge="185.245.183.110"
185.245.183.110 - - [20/Sep/2026:07:32:17 +0000] "GET /?author=6 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0" "-" edge="185.245.183.110"
...
show less
Web App Attack
๐ฉ๐ช
maxpower
2026-09-20 01:07:21
(15 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 185.245.183.110 (FR/France/vs8.logic-sys.com): ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 185.245.183.110 (FR/France/vs8.logic-sys.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 185.245.183.110 - - [20/Sep/2026:03:07:16 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12099 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0" "-" host=archabi.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 22:01:05
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 18:01:01.625727 2026] [security2:error] [pid 29956:tid 29956] [client 185.245.183.110:41336] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.marshdcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.marshdcs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8GHcewxuDrUHDyvgKyJQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 19:44:17
(20 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 18:39:27
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:39:19.905880 2026] [security2:error] [pid 5691:tid 5691] [client 185.245.183.110:43008] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greenmountainfeeds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greenmountainfeeds.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7W14THQOZgiCxzydHo_gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-19 16:33:42
(23 hours ago)
Probing websites for vulnerabilities
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 16:26:23
(1 day ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 15:12:46
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 11:12:40.672406 2026] [security2:error] [pid 18751:tid 18751] [client 185.245.183.110:57958] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonesband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonesband.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6maI0hE59DVMeABH1SIgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-19 15:02:11
(1 day ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-17 16:09:23
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:09:15.482422 2026] [security2:error] [pid 12697:tid 12697] [client 185.245.183.110:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rodrigoaldecoa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqwQqx7nM_Sw4yEtan-Y4wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-17 11:06:36
(3 days ago)
185.245.183.110 - - [17/Sep/2026:11:05:38 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 ...
show more
185.245.183.110 - - [17/Sep/2026:11:05:38 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "-" edge="185.245.183.110"
185.245.183.110 - - [17/Sep/2026:11:05:40 +0000] "GET /?author=3 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" "-" edge="185.245.183.110"
185.245.183.110 - - [17/Sep/2026:11:05:42 +0000] "GET /?author=4 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0" "-" edge="185.245.183.110"
185.245.183.110 - - [17/Sep/2026:11:05:44 +0000] "GET /?author=5 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0" "-" edge="185.245.183.110"
185.245.183.110 - - [17/Sep/2026:11:05:46 +0000] "GET /?author=6 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0" "-" edge="185.245.183.110"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 07:20:05
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 03:19:55.557608 2026] [security2:error] [pid 31087:tid 31189] [client 185.245.183.110:59882] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||metropaint.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "metropaint.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aquUm4b__CDll7-JpoXm6wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 04:43:56
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 185.245.183.110 (vs8.logic-sys.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:43:48.667489 2026] [security2:error] [pid 12464:tid 12517] [client 185.245.183.110:36680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sloveniaflyfishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sloveniaflyfishing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqtwBNEWWWt5vu4hNBxALAAAAdM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-15 04:53:00
(5 days ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection