๐ณ๐ฑ
Roderic
2026-09-30 07:13:57
(3 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ซ๐ท
dynamix
2026-09-26 22:59:10
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob
2026-09-15 10:47:56
(2 weeks ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /robots.txt | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36/Nutch-1.23-SNAPS | 2026-09-15 10:47 UTC
show less
Bad Web Bot
๐บ๐ธ
nationaleventpros.com
2026-09-05 05:16:24
(4 weeks ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-04 22:05:49
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:05:44.830106 2026] [security2:error] [pid 28411:tid 28411] [client 185.61.219.181:21201] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dcwenger.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dcwenger.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aptAuDi5_EJxXFA7Pme83wAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-09-03 01:33:19
(1 month ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-02 21:05:42
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 17:05:37.355325 2026] [security2:error] [pid 28535:tid 28535] [client 185.61.219.181:10161] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ngmweb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ngmweb.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apiPoc331hwONGMcZpIVawAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-17 20:10:03
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-11 14:10:03
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 20:00:40
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 16:00:32.386344 2026] [security2:error] [pid 2820028:tid 2820081] [client 185.61.219.181:29963] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||transitionalcareservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "transitionalcareservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anot4OvVvqHjiQKs7CCeUgAAAE0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-08-06 12:40:23
(1 month ago)
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-03 14:54:50
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 10:54:45.305995 2026] [security2:error] [pid 3355648:tid 3355648] [client 185.61.219.181:19687] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mrpinman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mrpinman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anCrtZJoDVMD4OjjUm18SwAAABQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-02 22:40:47
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.219.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 18:40:41.110660 2026] [security2:error] [pid 297520:tid 297520] [client 185.61.219.181:12373] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||contractorspecializing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "contractorspecializing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "am_HaW65rlFpA4-ayS6EdgAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-31 18:21:23
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
HighWay
2026-07-30 05:03:55
(2 months ago)
185.61.219.181 - - [30/Jul/2026:05:03:51 +0000] "POST /xmlrpc.php HTTP/1.1" 403 4410 "-" "Apache-Htt ...
show more
185.61.219.181 - - [30/Jul/2026:05:03:51 +0000] "POST /xmlrpc.php HTTP/1.1" 403 4410 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
185.61.219.181 - - [30/Jul/2026:05:03:52 +0000] "GET /wp-login.php HTTP/1.1" 404 4759 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
185.61.219.181 - - [30/Jul/2026:05:03:53 +0000] "GET /wp-login.php HTTP/1.1" 404 4759 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack