🇩🇪
C C
2026-08-14 22:43:01
(3 weeks ago)
Distributed scraping attack: 2168 req from 2069 rotating proxy IPs | this IP: 1 req
Open Proxy
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 06:48:13
(3 months ago)
[osotir.org] httpd-login-spray-site: sites=agonistes.gr.synathlountes; logs=/var/log/httpd/domains/a ...
show more
[osotir.org] httpd-login-spray-site: sites=agonistes.gr.synathlountes; logs=/var/log/httpd/domains/agonistes.gr.synathlountes.log; samples=site_wide=true | distinct_ips=30 | /wp-login.php
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-05-04 04:04:44
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 00:04:37.804555 2026] [security2:error] [pid 25018:tid 25018] [client 193.202.81.113:19515] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gotdt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gotdt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afga1RpL55zn5WuVwef5DAAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-01 11:03:08
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 07:03:03.842428 2026] [security2:error] [pid 14223:tid 14223] [client 193.202.81.113:63653] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||varalla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "varalla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afSIZ20Kw0QJw9lmcEwaTwAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-28 12:25:15
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 08:25:10.951303 2026] [security2:error] [pid 16926:tid 16926] [client 193.202.81.113:59583] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||deanfountain.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "deanfountain.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afCnJqFtb8vonWcmPx_k9wAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-14 15:30:50
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 11:30:45.859490 2026] [security2:error] [pid 2678638:tid 2678638] [client 193.202.81.113:21747] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||texaslawman.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "texaslawman.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ad5dpTXDSuag5mh_nEXKNQAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-03-09 00:41:21
(5 months ago)
Fail2Ban banned 193.202.81.113 for security violations in jail nginx-aggressive. Log: 2026/03/09 00: ...
show more
Fail2Ban banned 193.202.81.113 for security violations in jail nginx-aggressive. Log: 2026/03/09 00:41:19 [error] FastCGI sent in stderr: "Primary script unknown" , client: 193.202.81.113, server: [REDACTED], request: "POST /wp-admin/xmlrpc.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED]
2026/03/09 00:41:21 [error] FastCGI sent in stderr: "Primary script unknown" , client: 193.202.81.113, server: [REDACTED], request: "POST /wp-admin/xmlrpc.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2025-11-01 01:04:00
(10 months ago)
WordPress login attempt
Brute-Force
Anonymous
2025-10-29 14:09:14
(10 months ago)
Forum/form spam
Web Spam
🇮🇹
alph44
2025-10-22 01:08:00
(10 months ago)
WordPress attack detected by fail2ban: 3 failed attempts
Web App Attack
🇳🇱
mawan
2025-10-13 15:03:22
(10 months ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
🇫🇮
JimArchon72
2025-09-01 02:35:02
(1 year ago)
2025/09/01 02:31:35 "GET /wp-login.php HTTP/1.1"
Web App Attack
Anonymous
2025-04-02 08:43:12
(1 year ago)
Probing to gain illegal access
Web App Attack
🇨🇦
wil.com
2025-03-28 08:38:57
(1 year ago)
GlobalProtect login attempts with user JESSEB.
VPN IP
Brute-Force
🇦🇺
weblite
2023-12-20 04:52:14
(2 years ago)
WP_LOGIN_FAIL
Brute-Force
Web App Attack