π«π·
Feelautom
2026-06-11 18:07:07
(1 week ago)
[FeelAutom Auto-Ban] AI Analyst: Score de menace 122/200, comportement malveillant (Score: 222)
Hacking
π΅π±
strefapi_com
2026-06-10 13:46:00
(1 week ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
π§πͺ
cmbplf
2026-06-10 13:45:11
(1 week ago)
62.895 requests with url.path */xmlrpc.php
62.807 requests with url.path //xmlrpc.php
2.763 reque ...
show more
62.895 requests with url.path */xmlrpc.php
62.807 requests with url.path //xmlrpc.php
2.763 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-10 13:44:36
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 207.175.14.107 (107.14.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 207.175.14.107 (107.14.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 09:44:32.441855 2026] [security2:error] [pid 6122:tid 6122] [client 207.175.14.107:62101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||speedgo.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "speedgo.mx"] [uri "/wp-json/wp/v2/users/"] [unique_id "ailqQMsFNwf713lFPJ78IQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
NXTwoThou
2026-06-10 13:43:51
(1 week ago)
BadRequest
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 13:27:56
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 207.175.14.107 (107.14.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 207.175.14.107 (107.14.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 09:27:52.420473 2026] [security2:error] [pid 2561:tid 2561] [client 207.175.14.107:64143] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soundtrax.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ailmWLh0G86xRq72hmkP5wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
SoteriaCovenant
2026-06-10 13:27:25
(1 week ago)
Automated probe: /wp-includes/ID3/license.txt on Soteria Global infrastructure. No vulnerable softwa ...
show more
Automated probe: /wp-includes/ID3/license.txt on Soteria Global infrastructure. No vulnerable software present.
show less
Hacking
Anonymous
2026-06-10 13:24:06
(1 week ago)
207.175.14.107 - - [10/Jun/2026:15:24:03 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 511 ...
show more
207.175.14.107 - - [10/Jun/2026:15:24:03 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 51134 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
207.175.14.107 - - [10/Jun/2026:15:24:03 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 51538 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
207.175.14.107 - - [10/Jun/2026:15:24:04 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 51408 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
207.175.14.107 - - [10/Jun/2026:15:24:05 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 51167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
207.175.14.107 - - [10/Jun/2026:15:24:05 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.
...
show less
Brute-Force
Web App Attack
π¨π
Ribeye375
2026-06-10 13:17:13
(1 week ago)
HIPS rce-attempt - Block tcp/0:65535
Hacking
Web App Attack
π©πͺ
webanyone
2026-06-10 13:15:27
(1 week ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
π«π·
Feelautom
2026-06-10 13:11:35
(1 week ago)
[FeelAutom Auto-Ban] AI Analyst: Scan de chemins WordPress (PathScan) sur 6 occurrences
Port Scan
πΊπΈ
TPI-Abuse
2026-06-10 13:08:17
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 207.175.14.107 (107.14.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 207.175.14.107 (107.14.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 09:08:11.370864 2026] [security2:error] [pid 10216:tid 10216] [client 207.175.14.107:50885] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "solarfarms.info"] [uri "/wp-json/wp/v2/users/"] [unique_id "ailhu7OuBW0vQjKPbQNLCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-06-10 13:07:03
(1 week ago)
10 attempts against mh_ha-misc-ban on sonic
Brute-Force
Web App Attack
π·πΊ
DZBOT
2026-06-10 13:06:30
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-06-10 13:05:52
(1 week ago)
wordpress exploit scan
Web App Attack