๐ง๐ช
taivas.nl
2026-08-29 04:33:25
(3 days ago)
Many_bad_calls
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-29 04:28:33
(3 days ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
Anonymous
2026-08-29 01:12:36
(3 days ago)
2026-08-29T03:12:34.008731+02:00 aion wordpress[4151527]: Blocked user enumeration attempt from 188. ...
show more
2026-08-29T03:12:34.008731+02:00 aion wordpress[4151527]: Blocked user enumeration attempt from 188.166.239.157
...
show less
Hacking
Brute-Force
๐ฆ๐บ
paulshipley.com.au
2026-08-29 01:09:31
(3 days ago)
indigi-print-merch.com.au:443 188.166.239.157 - - [29/Aug/2026:11:09:28 +1000] "GET /?author=2 HTTP/ ...
show more
indigi-print-merch.com.au:443 188.166.239.157 - - [29/Aug/2026:11:09:28 +1000] "GET /?author=2 HTTP/1.1" 404 314046 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:03:01
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 188.166.239.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.239.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:02:56.898691 2026] [security2:error] [pid 21269:tid 21269] [client 188.166.239.157:60978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||letmespeakpodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "letmespeakpodcast.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apIvwDZi2josHEGBAi21bgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-08-29 00:42:28
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-29 00:42 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-29 00:22:50
(3 days ago)
WordPress Brute Force
Brute-Force
๐น๐ท
ycoskun41
2026-08-28 23:52:14
(3 days ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
omc
2026-08-28 23:37:47
(3 days ago)
Unauthorized file [PP].
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 23:21:05
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 188.166.239.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.239.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:20:58.496203 2026] [security2:error] [pid 26938:tid 26938] [client 188.166.239.157:34292] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coolerboxes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coolerboxes.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apIX2uaI-X4SeaP-Z7PsIAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-28 23:14:15
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:56:57
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 188.166.239.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.239.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:56:50.306532 2026] [security2:error] [pid 32008:tid 32008] [client 188.166.239.157:48606] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sherinemec-wies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sherinemec-wies.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apISMpbRr6x2WrC1d4LMJAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CollideTech
2026-08-28 21:44:44
(3 days ago)
probing for vulnerabilities
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-08-28 21:06:03
(3 days ago)
Wordfence waf block on registrymatters
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 21:05:47
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 188.166.239.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.239.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:05:42.593885 2026] [security2:error] [pid 10840:tid 10840] [client 188.166.239.157:41608] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barigby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barigby.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apH4JrgRQMI5Q2HRU8c_YwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack