๐บ๐ธ
RAP
2026-05-24 04:55:43
(3 months ago)
2026-05-24 04:55:43 UTC Unauthorized activity to TCP port 8080. Web App
Port Scan
Web App Attack
๐ฎ๐ณ
evicky2002
2026-05-02 06:00:00
(4 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-04-30 05:30:02
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 198.199.77.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 198.199.77.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 01:29:56.259577 2026] [security2:error] [pid 17156:tid 17156] [client 198.199.77.19:50108] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.batesstrategygroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.batesstrategygroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "afLo1LZMCIs5H6gdhu6yXAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
strefapi_com
2026-04-30 04:32:13
(4 months ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 02:22:32
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 198.199.77.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 198.199.77.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 22:22:24.709644 2026] [security2:error] [pid 693:tid 693] [client 198.199.77.19:53709] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bamedica.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "afK84GV0z4Lc_PCxJCN_gwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-04-30 02:06:23
(4 months ago)
(PERMBLOCK) 198.199.77.19 (US/United States/-) has had more than 4 temp blocks
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-30 01:05:39
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 198.199.77.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 198.199.77.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 21:05:31.606725 2026] [security2:error] [pid 3315:tid 3315] [client 198.199.77.19:58952] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.badconsultingllc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.badconsultingllc.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "afKq24n-Sw1gO3-psJKnjQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-30 01:03:15
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
integrantservices.com
2026-04-30 01:02:18
(4 months ago)
(wordpress) Failed wordpress login from 198.199.77.19 (US/United States/-)
Brute-Force
๐ฉ๐ช
abdubhai
2026-04-29 23:59:35
(4 months ago)
198.199.77.19 - - [30/Apr/2026:0
...
Brute-Force
๐ฉ๐ช
Ba-Yu
2026-04-29 23:26:30
(4 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
Anonymous
2026-04-29 23:05:27
(4 months ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=17
Hacking
Anonymous
2026-04-29 22:02:35
(4 months ago)
Web attack
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 20:13:43
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 198.199.77.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 198.199.77.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 16:13:35.373065 2026] [security2:error] [pid 26402:tid 26402] [client 198.199.77.19:62913] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.avvmarchetticollini.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.avvmarchetticollini.it"] [uri "/wp-json/wp/v2/users/"] [unique_id "afJmb_85OPtZEPW8fp3AhAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-04-29 20:05:42
(4 months ago)
ave-7 : Trying access unauthorized files/dir=>/wp-includes/wlwmanifest.xml
Hacking