๐ฉ๐ช
FeG Deutschland
2026-06-18 01:49:31
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 17:33:27
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 13:33:20.030635 2026] [security2:error] [pid 25304:tid 25304] [client 193.31.126.237:33885] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bhgvh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bhgvh.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aixC4NETIz7zlHGAfHJIWgAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 06:38:10
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 02:38:06.631863 2026] [security2:error] [pid 31715:tid 31715] [client 193.31.126.237:22625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gkwire.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gkwire.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aikGTn7zwXTi34KeEtfbRAAAAFE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 03:15:43
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 23:15:36.721284 2026] [security2:error] [pid 4678:tid 4678] [client 193.31.126.237:39985] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||serpentstudios.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "serpentstudios.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiOQ2JZf_s0AVGKU8Gul3AAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 19:59:31
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 15:59:27.127619 2026] [security2:error] [pid 13868:tid 13868] [client 193.31.126.237:58109] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brentsagnotti.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brentsagnotti.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahyTHxQ85CE9g1p5bcNYjAAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-08 07:47:16
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 13:02:05
(1 month ago)
(mod_security) mod_security (id:218580) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 193.31.126.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 09:02:01.321536 2026] [security2:error] [pid 14414:tid 14414] [client 193.31.126.237:35859] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:id. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||listings.cruisingforsex.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "listings.cruisingforsex.com"] [uri "/postreply.php"] [unique_id "afyNSQqYpv_sx02GIVuaOwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-10 14:34:53
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-05-17 12:47:35
(1 year ago)
WP Login Scan Activities
Web App Attack
๐ธ๐ช
OnTheEdge
2025-03-06 04:12:06
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ต๐ฑ
sefinek.net
2024-08-30 11:56:06
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15 Safari/605.1.15 - -
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2024-08-30 11:56:06
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15 Safari/605.1.15 - -
show less
Bad Web Bot
๐บ๐ธ
tropicalidad.be
2021-05-05 17:38:25
(5 years ago)
blog comment/referrer spam
Web Spam
๐ฉ๐ฐ
bredelund.dk
2021-04-28 19:27:59
(5 years ago)
Scanning for vulnerabilities
Hacking
Web App Attack
๐บ๐ธ
tropicalidad.be
2021-04-22 06:10:32
(5 years ago)
blog comment/referrer spam
Web Spam