🇩🇪
FeG Deutschland
2026-09-08 16:33:06
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-08 15:50:34
(1 hour ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 15:30:22
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 193.121.133.8 (8.133-121-193.fia-dyn.isp.proxim ...
show more
(mod_security) mod_security (id:225170) triggered by 193.121.133.8 (8.133-121-193.fia-dyn.isp.proximus.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:30:16.714385 2026] [security2:error] [pid 15178:tid 15178] [client 193.121.133.8:38396] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.market1st.bridgital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.market1st.bridgital.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAqCMbCvpU8jCYI0sMjugAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:58:37
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 193.121.133.8 (8.133-121-193.fia-dyn.isp.proxim ...
show more
(mod_security) mod_security (id:225170) triggered by 193.121.133.8 (8.133-121-193.fia-dyn.isp.proximus.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:58:33.029364 2026] [security2:error] [pid 1290:tid 1290] [client 193.121.133.8:58568] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||renjunews.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "renjunews.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAimcMYoOAb25VVRWHTvwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:45:43
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 193.121.133.8 (8.133-121-193.fia-dyn.isp.proxim ...
show more
(mod_security) mod_security (id:225170) triggered by 193.121.133.8 (8.133-121-193.fia-dyn.isp.proximus.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:45:38.191112 2026] [security2:error] [pid 8226:tid 8226] [client 193.121.133.8:57720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||plazahacienda.imerka.com.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "plazahacienda.imerka.com.mx"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_ZQq6aN2wY6Q-S3Yp9TAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:01:12
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 193.121.133.8 (8.133-121-193.fia-dyn.isp.proxim ...
show more
(mod_security) mod_security (id:225170) triggered by 193.121.133.8 (8.133-121-193.fia-dyn.isp.proximus.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:01:05.116126 2026] [security2:error] [pid 10193:tid 10193] [client 193.121.133.8:52900] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kerrywood.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kerrywood.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_O0YtOiuhkGgBGEkfDugAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 03:47:10
(13 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-08 03:47 UTC
Brute-Force
Web App Attack
🇸🇬
garrymenata
2026-08-24 00:38:25
(2 weeks ago)
193.121.133.8 - - [24/Aug/2026:01:47:18 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U ...
show more
193.121.133.8 - - [24/Aug/2026:01:47:18 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
193.121.133.8 - - [24/Aug/2026:01:47:20 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
193.121.133.8 - - [24/Aug/2026:01:47:22 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
...
show less
DDoS Attack
Bad Web Bot
🇵🇱
mkey
2026-04-12 23:45:02
(4 months ago)
Multiple ports scan detected locally. (3 probes in last hour, last seen 2026-04-13 01:34:00)
Port Scan
🇫🇷
ISPLtd
2026-04-11 10:52:26
(4 months ago)
Apr 11 12:52:22 193.121.133.8 TCP SPT=45588 DPT=5555 SYN
Apr 11 12:52:23 193.121.133.8 TCP SPT=45588 ...
show more
Apr 11 12:52:22 193.121.133.8 TCP SPT=45588 DPT=5555 SYN
Apr 11 12:52:23 193.121.133.8 TCP SPT=45588 DPT=5555 SYN
Apr 11 12:52:25 193.121.133.8 TCP SPT=45588 DPT=5555
...
show less
Port Scan
🇺🇸
MPL
2026-04-11 10:11:14
(4 months ago)
tcp/5555 (9 or more attempts)
Port Scan
🇳🇱
EGP Abuse Dept
2026-04-10 10:04:02
(4 months ago)
Port connection indicating compromised host
Port Scan
Hacking
Exploited Host
🇩🇪
london2038.com
2026-04-09 11:36:33
(4 months ago)
2026-04-09 13:35:52.157 5555/TCP connection CID-1453 failed from 193.121.133.8 (8.133-121-193.fia-dy ...
show more
2026-04-09 13:35:52.157 5555/TCP connection CID-1453 failed from 193.121.133.8 (8.133-121-193.fia-dyn.isp.proximus.be), port 54334
show less
Port Scan
🇬🇧
2048
2026-04-09 07:17:33
(4 months ago)
2026-04-09T08:17:28.529489+01:00 machodeer kernel: [3975868.212933] [UFW BLOCK] IN=ens3 OUT= MAC=RED ...
show more
2026-04-09T08:17:28.529489+01:00 machodeer kernel: [3975868.212933] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=193.121.133.8 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=42838 DF PROTO=TCP SPT=35044 DPT=5555 WINDOW=65535 RES=0x00 SYN URGP=0
2026-04-09T08:17:29.552874+01:00 machodeer kernel: [3975869.236421] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=193.121.133.8 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=42839 DF PROTO=TCP SPT=35044 DPT=5555 WINDOW=65535 RES=0x00 SYN URGP=0
2026-04-09T08:17:31.771075+01:00 machodeer kernel: [3975871.454320] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=193.121.133.8 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=42840 DF PROTO=TCP SPT=35044 DPT=5555 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
🇺🇸
MPL
2026-04-08 23:41:22
(4 months ago)
tcp/5555 (6 or more attempts)
Port Scan