๐ฉ๐ช
Ilop
2026-09-02 00:01:25
(6 hours ago)
[hp-100] 19 unsolicited packets to honeypot ports 8000 (OCI DShield sensor)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-16 14:02:18
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 10:02:14.612249 2026] [security2:error] [pid 19812:tid 19812] [client 185.96.37.53:42711] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||delucchi.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "delucchi.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajFXZg0NDfxqWV1xyBM_SwAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-06-14 18:44:14
(2 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
kosada.com
2026-06-11 03:51:49
(2 months ago)
Web password guessing
Brute-Force
Anonymous
2026-06-09 05:05:29
(2 months ago)
[redacted] 185.96.37.53 - - [09/Jun/2026:07:05:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Ap ...
show more
[redacted] 185.96.37.53 - - [09/Jun/2026:07:05:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 185.96.37.53 - - [09/Jun/2026:07:05:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 222 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 185.96.37.53 - - [09/Jun/2026:07:05:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 185.96.37.53 - - [09/Jun/2026:07:05:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 245 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 185.96.37.53 - - [09/Jun/2026:07:05:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 245 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 185.96.37.53 - - [09/Jun/2026:07:05:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 245 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 185.96.37.53 - - [09/Jun/2026:07:05:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 245 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-05-30 15:06:58
(3 months ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-29 02:27:07
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 22:27:00.726254 2026] [security2:error] [pid 4887:tid 4887] [client 185.96.37.53:60777] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||liberlibro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "liberlibro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahj5dLg5m7o3qH2hiJIfuAAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 18:35:06
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 14:35:02.630659 2026] [security2:error] [pid 2878:tid 2878] [client 185.96.37.53:9221] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oxfordgrpco.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oxfordgrpco.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahSWVkebKMxYxvZIhl7gKwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 05:40:23
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 01:40:20.506375 2026] [security2:error] [pid 4520:tid 4617] [client 185.96.37.53:18193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aiegroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aiegroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag6axESktlsMo91tI7IwNQAAAck"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-05-20 22:20:14
(3 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 19:09:14
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 15:09:07.769224 2026] [security2:error] [pid 17102:tid 17102] [client 185.96.37.53:21571] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||enfiestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "enfiestate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abG90_P3Tex0Jswehg-sXAAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-07 20:22:29
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.96.37.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 07 15:22:22.981228 2026] [security2:error] [pid 27701:tid 27701] [client 185.96.37.53:18531] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||p-co.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "p-co.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aayI_ixn_UfYesGQ_mKDeAAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2025-12-27 20:28:18
(8 months ago)
(wordpress) Failed wordpress login from 185.96.37.53 (RU/Russia/-/-/-/[redacted])
Brute-Force
Anonymous
2025-10-01 11:23:08
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
hostseries
2025-09-25 12:39:28
(11 months ago)
Trigger: LF_DISTATTACK
Brute-Force