๐ซ๐ท
Sklurk
2026-08-23 12:52:13
(4 days ago)
Web App Attack
Web App Attack
๐ฉ๐ฐ
RhQM
2026-08-23 12:45:15
(4 days ago)
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:32:23
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:32:16.885651 2026] [security2:error] [pid 6937:tid 6937] [client 2.29.10.228:43446] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jerryfeil.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jerryfeil.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoraQGBnCXZBJB6CiyLqDQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 10:32:14
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 06:32:07.259636 2026] [security2:error] [pid 21152:tid 21152] [client 2.29.10.228:27576] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desertalfas.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desertalfas.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aorMJ9q4MzKFaxHE1QQIxAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-23 10:09:42
(4 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.10.228 (FI/Finland/static.228.10.29.2.cli ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.10.228 (FI/Finland/static.228.10.29.2.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2.29.10.228 - - [23/Aug/2026:12:09:40 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 404 355 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=dimensioneautosgt.it
show less
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-08-23 10:05:20
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 09:45:07
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:45:02.698673 2026] [security2:error] [pid 12812:tid 12812] [client 2.29.10.228:46266] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fusionrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fusionrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorBHm47Y6tP-SNH6gExTwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 22:52:57
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 18:52:53.823652 2026] [security2:error] [pid 11293:tid 11293] [client 2.29.10.228:42496] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dvdmasters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dvdmasters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoooRcLvbbTrJDXvQ-a2tAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
svejk
2026-08-22 22:42:00
(4 days ago)
[23/Aug/2026:02:03:31 +0930] "GET / HTTP/1.1" 444 0 ... Ports scanning nuisance/abuse. Banned!
Port Scan
Bad Web Bot
Phishing
Anonymous
2026-08-22 20:15:43
(4 days ago)
GET / HTTP/1.1
Port Scan
Hacking
๐ฉ๐ช
LRob
2026-08-22 16:37:20
(4 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 16:00:47
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 12:00:42.407410 2026] [security2:error] [pid 24291:tid 24291] [client 2.29.10.228:44884] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||holgerfeld.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "holgerfeld.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aonHqgQUTH8VNjuLWLblTwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-08-22 15:54:35
(4 days ago)
connection to honeypot
Email Spam
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-22 15:43:23
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:43:16.916414 2026] [security2:error] [pid 32385:tid 32385] [client 2.29.10.228:39460] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||texastraumarecovery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "texastraumarecovery.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aonDlAKLsUbvVCECgflt9gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 11:08:33
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.228 (static.228.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 07:08:27.826660 2026] [security2:error] [pid 16406:tid 16406] [client 2.29.10.228:48974] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newcitypark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newcitypark.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomDK1r3atth19o_vMCTdAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack