๐ฉ๐ช
Oakley
2026-05-19 21:54:31
(2 weeks ago)
(mod_security) mod_security (id:900210) triggered by 185.77.223.90 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:900210) triggered by 185.77.223.90 (US/United States/-): 5 in the last 900 secs
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-25 17:24:11
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.77.223.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.77.223.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 13:24:06.164330 2026] [security2:error] [pid 7743:tid 7743] [client 185.77.223.90:39505] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aaattanasio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aaattanasio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aez4tkEDAZ7yD7Slz172DgAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-04-24 10:51:14
(1 month ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 185.77.223.90 (US/United States/-): 1 in the ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 185.77.223.90 (US/United States/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 185.77.223.90 - - [24/Apr/2026:13:51:11 +0300] "GET /wp-login.php HTTP/2.0" 200 2919 "-" "Go-http-client/2.0"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-24 06:44:20
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.77.223.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.77.223.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 24 02:44:12.491697 2026] [security2:error] [pid 21174:tid 21174] [client 185.77.223.90:47041] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stoneybluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stoneybluff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aesRPBFc0oG-9AYSfIH8twAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 01:37:46
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 185.77.223.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.77.223.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 21:37:40.989568 2026] [security2:error] [pid 2248962:tid 2248962] [client 185.77.223.90:16729] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Jefferson/Thumbs.db"] [unique_id "aeA9ZFSrEUUmio_TUjCuwAAAACE"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Jefferson/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-03-26 21:42:01
(2 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ง๐ช
voormedia
2026-02-09 05:09:19
(3 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-02-08 06:30:24
(3 months ago)
XML RPC Scan Activities
Brute-Force
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-02-05 12:12:29
(4 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
๐ฎ๐ฉ
sockominfo
2026-02-05 09:00:31
(4 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-05 07:56:07
(4 months ago)
[WAZUH] Mixed case extension detected (case variation bypass)
Hacking
Web App Attack
Anonymous
2026-02-03 22:05:29
(4 months ago)
"POST /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 00:40:34
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 185.77.223.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 185.77.223.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 19:40:19.553145 2026] [security2:error] [pid 28807:tid 28807] [client 185.77.223.90:35815] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tactara.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tactara.net"] [uri "/"] [unique_id "aWWUc78naMu8jTgZMlkG2gAAADY"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-01-12 07:25:06
(4 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
nowyouknow
2025-12-16 18:45:12
(5 months ago)
(From [email protected] ) Hi Team,
I typed your main service keywords into Google tod ...
show more
(From [email protected] ) Hi Team,
I typed your main service keywords into Google today, and I noticed something frustrating. Your website is professionally designed, but itโs buried on Page 2.
Meanwhile, 2 or 3 of your direct competitors, who frankly have weaker websites than youโare sitting at the top of Page 1.
They are effectively "stealing" leads that were looking for you. They aren't better than you; they just have better SEO signals.
Iโve already analyzed exactly what they are doing differently.
If you want to see the comparison report, just reply "Yes" and Iโll send it over.
Cheers,
PMP
show less
Phishing
Web Spam