๐บ๐ธ
TPI-Abuse
2026-03-30 04:20:36
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.221.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.221.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 00:20:32.915840 2026] [security2:error] [pid 31439:tid 31439] [client 185.61.221.93:50739] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pourier.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pourier.net"] [uri "/wp-json/wp/v2/users"] [unique_id "acn6EM_mQgjIu_y0mAotngAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 19:20:49
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.221.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.221.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 15:20:42.351110 2026] [security2:error] [pid 30142:tid 30142] [client 185.61.221.93:50123] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||k-h-w.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "k-h-w.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abr7CinBNH4JSGwrsYoWKAAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-16 21:55:45
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.61.221.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.61.221.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 17:55:40.119625 2026] [security2:error] [pid 8317:tid 8317] [client 185.61.221.93:25687] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rendermatrix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rendermatrix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abh8XA-Qv-0GFlNx-86lKgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DaleCooper
2026-03-07 09:36:15
(2 months ago)
185.61.221.93 - - [07/Mar/2026:10:36:01 +0100] "GET /wp-login.php HTTP/1.1" 404 188 "https://www.goo ...
show more
185.61.221.93 - - [07/Mar/2026:10:36:01 +0100] "GET /wp-login.php HTTP/1.1" 404 188 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
185.61.221.93 - - [07/Mar/2026:10:36:02 +0100] "GET /wp-login.php HTTP/1.1" 404 188 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ฉ๐ช
HandyTreff.de
2026-01-07 06:30:42
(4 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -25.001 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -25.001 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2024-08-30 11:55:09
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (iPhone; CPU iPhone OS 9_0_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/88.0.4324.182 Mobile/13A404 Safari/604.1 - -
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2024-08-30 11:55:09
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (iPhone; CPU iPhone OS 9_0_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/88.0.4324.182 Mobile/13A404 Safari/604.1 - -
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2024-06-09 21:23:00
(1 year ago)
DDoS Attack Layer 7 - REQUESTS / HTTP/2.0
DDoS Attack
๐ฉ๐ช
SCHAPPY
2023-07-26 18:51:04
(2 years ago)
IP was involved in L7 DDoS attack.
DDoS Attack
๐ฌ๐ง
Keratin
2023-05-18 08:56:27
(3 years ago)
Possible web app exploitation
Brute-Force
Web App Attack
๐บ๐ธ
RLDD
2023-03-26 22:23:51
(3 years ago)
WP probing for vulnerabilities -ver
Web App Attack
๐ช๐ธ
10dencehispahard SL
2023-03-22 09:25:21
(3 years ago)
Unauthorized login attempts [ wordpress]
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2021-02-09 08:35:23
(5 years ago)
Brute-Force