πͺπΈ
librebit
2026-08-11 03:55:28
(1 week ago)
Brute force
Brute-Force
π·π΄
magefix
2026-07-31 04:31:00
(3 weeks ago)
Fraudulent orders placed through WooCommerce store using stolen/fake customer and payment informatio ...
show more
Fraudulent orders placed through WooCommerce store using stolen/fake customer and payment information.
show less
Fraud Orders
πΊπΈ
TPI-Abuse
2026-07-19 17:34:34
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 13:34:28.748722 2026] [security2:error] [pid 3517376:tid 3517376] [client 185.61.217.74:18055] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.powerkiteforum.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.powerkiteforum.com"] [uri "/"] [unique_id "al0KpGCpWGC5F3R_SBid6gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-13 21:14:25
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 17:14:16.835722 2026] [security2:error] [pid 4145504:tid 4145504] [client 185.61.217.74:55717] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||shirtzz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "shirtzz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad1cqFGE_R_jvT4vAc1gLAAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2026-04-12 03:42:03
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-04-09 18:55:19
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 14:55:14.484629 2026] [security2:error] [pid 966708:tid 966708] [client 185.61.217.74:59709] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prodigypartners.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prodigypartners.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adf2EuFAp6oQlVBlXmKY_wAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-01 14:48:52
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 09:48:46.241586 2026] [security2:error] [pid 5385:tid 5385] [client 185.61.217.74:17491] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bernsteinip.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aVaJThupU-o8MXMrEDzpMQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
grassau.com
2025-12-28 11:13:12
(7 months ago)
(wordpress) Failed wordpress login from 185.61.217.74 (RU/Russia/-)
Brute-Force
πΊπΈ
TPI-Abuse
2025-12-24 15:19:12
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.217.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 24 10:19:08.473512 2025] [security2:error] [pid 7623:tid 7623] [client 185.61.217.74:50613] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||walterceron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "walterceron.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aUwEbPKIp50OKFnENgpPOQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
NetGuard
2025-12-01 18:53:56
(8 months ago)
π¨ CRITICAL: Real-time threat on Tanner | unknown | Port 80 | PhantomGrid Real-time Defense
Hacking
π·πΊ
Agrohim
2025-11-12 00:27:38
(9 months ago)
Gate Inet blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
Anonymous
2025-11-09 11:38:55
(9 months ago)
Forum/form spam
Web Spam
π¬π§
essinghigh
2024-07-28 01:04:52
(2 years ago)
1722128691 # Service_probe # SIGNATURE_SEND # source_ip:185.61.217.74 # dst_port:60000
...
Port Scan
πΊπΈ
MrDD
2024-07-19 21:34:11
(2 years ago)
Brute force attempt on Cisco Web VPN
Brute-Force
π΅π±
TI
2023-10-28 09:57:39
(2 years ago)
Scrapping website, using diffrent useragents, not wait for response, #botnet20231026
DDoS Attack
Bad Web Bot