๐ฉ๐ช
BlueWire Hosting
2026-07-26 17:39:02
(13 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐จ๐ฆ
DRI
2026-07-26 03:34:58
(1 day ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 14:14:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 10:14:16.002969 2026] [security2:error] [pid 17075:tid 17096] [client 194.99.26.194:11149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||colinarchibald.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "colinarchibald.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alZEN7RKrLTPZR30K_dtlwAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-05-17 22:45:26
(2 months ago)
tcp/80; WordPress login page access attempt: "GET /wp-login.php" @ 2026-05-17T22:43:46Z [proxy]
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-05-10 09:13:01
(2 months ago)
Try to access /xmlrpc.php
Web App Attack
๐จ๐ญ
4server
2026-05-10 07:09:57
(2 months ago)
[SunMay1009:09:55.3884802026][security2:error][pid2379339:tid2379508][client194.99.26.194:0]ModSecur ...
show more
[SunMay1009:09:55.3884802026][security2:error][pid2379339:tid2379508][client194.99.26.194:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"xmlrpc\\\\\\\\.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/03_asl_dos.conf\"][line\"65\"][id\"392331\"][rev\"3\"][msg\"Atomicorp.comWAFRules:xmlrpcDOSattack\"][severity\"CRITICAL\"][hostname\"comarcosa.com\"][uri\"/xmlrpc.php\"][unique_id\"agAvQ6GHsDgbUiIX95pGdwAAAEg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
octageeks.com
2026-05-06 04:06:49
(2 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐ฉ๐ช
stinpriza
2026-05-04 13:31:59
(2 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 10:12:46
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 06:12:40.101291 2026] [security2:error] [pid 6764:tid 6764] [client 194.99.26.194:10567] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nashhouse.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nashhouse.us"] [uri "/wp-json/wp/v2/users"] [unique_id "acZYGGHxwlIX3E3LVvspWAAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:40:37
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:40:32.821403 2026] [security2:error] [pid 10658:tid 10658] [client 194.99.26.194:33791] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||guardmagic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "guardmagic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab4FIGiV8tyxgkBryQHZZAAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-17 12:05:10
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 17 08:05:05.049497 2026] [security2:error] [pid 6464:tid 6464] [client 194.99.26.194:53339] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||portraitsinblues.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "portraitsinblues.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ablDccHmdvwkzlwevUosfQAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-17 04:58:32
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 17 00:58:26.501892 2026] [security2:error] [pid 24861:tid 24861] [client 194.99.26.194:51093] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||memrfixitok.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "memrfixitok.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abjfcpy6qx2ksPYMA5TzzwAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-03-10 20:10:12
(4 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-21 13:56:33
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 194.99.26.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 21 08:56:28.581323 2025] [security2:error] [pid 20914:tid 20914] [client 194.99.26.194:21543] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||khaoula.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "khaoula.com"] [uri "/"] [unique_id "aUf8jDfIce5_Dj4xnvn9XQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-27 15:46:19
(1 year ago)
Failed Wordpress Logins
Web App Attack