๐ฉ๐ช
maxpower
2026-08-23 03:58:10
(4 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.13.119 (FI/Finland/static.119.13.29.2.cli ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.13.119 (FI/Finland/static.119.13.29.2.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2.29.13.119 - - [23/Aug/2026:05:58:08 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 404 355 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=ramsesconsulting.com
show less
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-08-23 03:54:43
(4 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-08-23 03:52:49
(4 hours ago)
2.29.13.119 (FI/Finland/static.119.13.29.2.clients.your-server.de), more than 7 Apache 403 hits
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-23 02:14:03
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 22:13:55.627840 2026] [security2:error] [pid 13347:tid 13371] [client 2.29.13.119:29514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||planillas.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "planillas.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aopXY-0nSi8-0TGD27CQWgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 01:48:17
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 21:48:14.046528 2026] [security2:error] [pid 21468:tid 21483] [client 2.29.13.119:19678] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||swizzlestick.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "swizzlestick.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aopRXlICIbIgYH9yPxbQtAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 00:31:08
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 20:31:02.195399 2026] [security2:error] [pid 10254:tid 10254] [client 2.29.13.119:27742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aimer.es|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aimer.es"] [uri "/wp-json/wp/v2/users"] [unique_id "aoo_RvH0zu2HJyfjvcxcaAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ddw
2026-08-22 21:27:59
(11 hours ago)
Access Violation Attempts - Multiple 403 Forbidden responses.
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-22 17:23:20
(15 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.13.119 (FI/Finland/static.119.13.29.2.cli ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.13.119 (FI/Finland/static.119.13.29.2.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2.29.13.119 - - [22/Aug/2026:19:23:17 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 7033 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=johnfante.info
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-22 14:43:36
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:43:29.330226 2026] [security2:error] [pid 21027:tid 21027] [client 2.29.13.119:21402] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ardath.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ardath.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aom1kRdKEMZ9BxY9LvVNFAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 12:48:47
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:48:43.715567 2026] [security2:error] [pid 31309:tid 31309] [client 2.29.13.119:40192] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||emsahara.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "emsahara.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aomaq_yRn_-7AOS8taeHhgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 12:18:26
(20 hours ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 12:08:56
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:08:51.035856 2026] [security2:error] [pid 3717:tid 3717] [client 2.29.13.119:30250] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marshvineyards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marshvineyards.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomRU2RhATQQVGlBRbSDaQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-08-22 12:00:15
(20 hours ago)
Triggered Cloudflare WAF from FI.
Action taken: LINK_MAZE_INJECTED
ASN: 24940 (Hetzner Online GmbH)
...
show more
Triggered Cloudflare WAF from FI.
Action taken: LINK_MAZE_INJECTED
ASN: 24940 (Hetzner Online GmbH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-08-22T11:21:04Z
User-Agent: Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)
show less
Bad Web Bot
๐ฉ๐ช
maxpower
2026-08-22 11:41:58
(20 hours ago)
(PERMBLOCK) 2.29.13.119 (FI/Finland/static.119.13.29.2.clients.your-server.de) has had more than 4 t ...
show more
(PERMBLOCK) 2.29.13.119 (FI/Finland/static.119.13.29.2.clients.your-server.de) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-22 11:29:53
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-se ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.13.119 (static.119.13.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 07:29:49.020856 2026] [security2:error] [pid 26541:tid 26541] [client 2.29.13.119:46192] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wildcomaui.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wildcomaui.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomILQbnPmSHZqtxFhL1eAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack