๐ง๐ช
Saec
2026-08-13 11:28:05
(2 weeks ago)
Jarvis auto-ban: CF honeypot path /xmlrpc.php (2ร on saec.me)
Port Scan
Web App Attack
๐ฎ๐น
VHosting
2026-08-07 19:50:03
(3 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
neogenius
2026-06-22 01:22:43
(2 months ago)
Web App Attack
Web App Attack
Brute-Force
๐บ๐ธ
kosada.com
2026-06-09 13:43:12
(2 months ago)
Web password guessing
Brute-Force
๐ฉ๐ช
joharikop
2026-05-31 17:17:51
(3 months ago)
Exploit scanning detected by fail2ban on nginx reverse proxy (wp-admin, .env, shell probes, phpmyadm ...
show more
Exploit scanning detected by fail2ban on nginx reverse proxy (wp-admin, .env, shell probes, phpmyadmin)
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 09:59:06
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 05:59:02.368683 2026] [security2:error] [pid 24589:tid 24589] [client 194.99.24.11:43561] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agL55hsGeN0tYdewQCxMzQAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Oakley
2026-05-05 09:47:10
(3 months ago)
(mod_security) mod_security (id:900209) triggered by 194.99.24.11 (US/United States/-): 5 in the las ...
show more
(mod_security) mod_security (id:900209) triggered by 194.99.24.11 (US/United States/-): 5 in the last 900 secs
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-10 07:54:55
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 03:54:50.943206 2026] [security2:error] [pid 2145028:tid 2145028] [client 194.99.24.11:28363] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mtalame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mtalame.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adisyoSurvVg0Xy3rnRuhQAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 23:37:46
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 19:37:39.131219 2026] [security2:error] [pid 14976:tid 14976] [client 194.99.24.11:46429] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sfprivatechef.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sfprivatechef.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acXDQ8fC5NY3u-MTXVTLsQAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 23:02:14
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 18:02:11.245380 2026] [security2:error] [pid 8606:tid 8606] [client 194.99.24.11:51167] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doreenkimura.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doreenkimura.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXKsc-PM2ffi0cW3QKmpIwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 12:36:16
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 07:36:12.453617 2026] [security2:error] [pid 26911:tid 26911] [client 194.99.24.11:32253] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||weddingmusicguitar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "weddingmusicguitar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIZvN8e3TAuHAMC2s07GgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 11:43:07
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 06:43:01.164722 2026] [security2:error] [pid 22283:tid 22283] [client 194.99.24.11:64727] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kavahawaii.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kavahawaii.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXINRXhINsrgspHiEV7RLgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-17 21:45:10
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 17 16:45:02.469729 2025] [security2:error] [pid 30882:tid 30882] [client 194.99.24.11:10285] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bohk.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bohk.com"] [uri "/"] [unique_id "aUMkXni8S1Xug3MzaYCI7QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 18:23:22
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 13:23:16.433298 2025] [security2:error] [pid 9507:tid 9507] [client 194.99.24.11:10821] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||macryder.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "macryder.com"] [uri "/"] [unique_id "aRjFFLrsM4Q_Z6lquCJ7HQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 16:43:13
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 194.99.24.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 11:43:06.563300 2025] [security2:error] [pid 19525:tid 19525] [client 194.99.24.11:42893] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||paladinmicro.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "paladinmicro.com"] [uri "/"] [unique_id "aRitmkcNX4R7HvJRyhMabQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack