🇨🇦
polycoda
2026-08-10 16:27:47
(3 weeks ago)
📄 Probes for tons of inexistent files and/or PHP scripts
Hacking
Web App Attack
🇩🇪
barbarella
2026-08-10 15:24:29
(3 weeks ago)
unauthorized access to Visual Studio Code - SFTP Extension (GET /wp-json/wc/v3/customers)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-10 15:20:13
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 11:20:06.274081 2026] [security2:error] [pid 3689937:tid 3689937] [client 195.38.168.118:35564] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.agri-stor.totalstorage.solutions|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.agri-stor.totalstorage.solutions"] [uri "/wp-json/wp/v2/users"] [unique_id "annsJn-2_IEIDW0j-zt7RAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-08-10 15:19:06
(3 weeks ago)
fail2ban: apache-random-recon
...
Web App Attack
🇩🇪
LRob
2026-08-10 15:00:17
(3 weeks ago)
WordPress REST-API user enumeration (probing CVE-2017-5487 to harvest usernames) | req: /wp-json/wp/ ...
show more
WordPress REST-API user enumeration (probing CVE-2017-5487 to harvest usernames) | req: /wp-json/wp/v2/users?per_page=100&_fields=slug,locale | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-10 14:57:29
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 10:57:20.562769 2026] [security2:error] [pid 8419:tid 8419] [client 195.38.168.118:43318] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bikinitweets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bikinitweets.com"] [uri "/wp-json/wp/v2/users"] [unique_id "annm0LG4-0DCsi5H7wQ9sQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
xxkodedxx
2026-08-10 14:16:24
(3 weeks ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
Active: 14:15:43 UTC
Volume: 1 honeypot probe(s)
Bait taken: /wp-json/wp/v2/users?_jsonp=callback&per_page=100&_fields=id,slug
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-08-10 14:11:43
(3 weeks ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-08-10 14:09:19
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 10:09:11.817397 2026] [security2:error] [pid 1147147:tid 1147147] [client 195.38.168.118:45134] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ewingmissouri.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ewingmissouri.com"] [uri "/wp-json/wp/v2/users"] [unique_id "annbhz1VDNsPkk4-mOw_wgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇷
setupgr
2026-08-10 13:55:50
(3 weeks ago)
(XMLRPC) WP XMLRPC Attack 195.38.168.118 (KG/Kyrgyzstan/Chuy Region/Lebedinovka/-/[AS8511 AS8511-AI ...
show more
(XMLRPC) WP XMLRPC Attack 195.38.168.118 (KG/Kyrgyzstan/Chuy Region/Lebedinovka/-/[AS8511 AS8511-AI Bishkek, Kyrgyzstan]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 195.38.168.118 - - [10/Aug/2026:16:45:18 +0300] "POST /xmlrpc.php HTTP/2.0" 503 7315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-08-10 13:53:34
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 09:53:25.485461 2026] [security2:error] [pid 30393:tid 30393] [client 195.38.168.118:54134] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||birdlovesfish.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "birdlovesfish.com"] [uri "/wp-json/wp/v2/users"] [unique_id "annX1dWro1wM0cul3qs2mgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-10 12:25:02
(3 weeks ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇩🇪
LRob
2026-08-10 12:10:03
(3 weeks ago)
WordPress REST-API user enumeration (probing CVE-2017-5487 to harvest usernames) | req: /wp-json/wp/ ...
show more
WordPress REST-API user enumeration (probing CVE-2017-5487 to harvest usernames) | req: /wp-json/wp/v2/users?per_page=50&_embed&_fields=id,slug,name | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-10 11:34:58
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 07:34:54.335034 2026] [security2:error] [pid 2820028:tid 2820085] [client 195.38.168.118:41228] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ward-bergerhouse.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ward-bergerhouse.org"] [uri "/wp-json/wp/v2/users"] [unique_id "anm3XuvVvqHjiQKs7CB4XAAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-10 10:34:59
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.38.168.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 06:34:50.044555 2026] [security2:error] [pid 2917127:tid 2917127] [client 195.38.168.118:51626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nekstlevel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nekstlevel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anmpSspaUaWi_ViryN3AJwAAABY"], referer: https://nekstlevel.com/
show less
Brute-Force
Bad Web Bot
Web App Attack