๐ฒ๐ฝ
octageeks.com
2026-06-22 04:10:01
(21 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐จ๐ฟ
huginet
2026-06-21 21:06:57
(1 day ago)
209.172.2.130 - - [21/Jun/2026:23:06:55 +0200] "GET /wp-login.php HTTP/1.1" 200 9112 "-" "Mozilla/5. ...
show more
209.172.2.130 - - [21/Jun/2026:23:06:55 +0200] "GET /wp-login.php HTTP/1.1" 200 9112 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
209.172.2.130 - - [21/Jun/2026:23:06:56 +0200] "POST /wp-login.php HTTP/1.1" 200 9549 "https://centrum-eko-likvidace.org/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web Spam
Blog Spam
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
georgengelmann
2026-06-20 14:54:40
(2 days ago)
Failed login attempt for bchpls
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 23:54:45
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 19:54:41.485187 2026] [security2:error] [pid 22637:tid 22637] [client 209.172.2.130:45876] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greatchristianadventure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greatchristianadventure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajXWwVtwO_A11-Qwnxlr7QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 23:15:58
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 19:15:51.179273 2026] [security2:error] [pid 5401:tid 5401] [client 209.172.2.130:50584] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jeanniemorrislaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jeanniemorrislaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajXNpx3QEDLuJZo2ghGniQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 20:07:10
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 16:07:03.288720 2026] [security2:error] [pid 12660:tid 12660] [client 209.172.2.130:39058] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||waterjetsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "waterjetsolutions.com"] [uri "/wp-json/wp/v2/users/7"] [unique_id "ajWhZ1HU-_QuUlzjIMdN3wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-19 20:05:51
(3 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 18:40:01
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 14:39:53.819069 2026] [security2:error] [pid 7320:tid 7320] [client 209.172.2.130:58814] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.plazahacienda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.plazahacienda.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWM-RZ6GR_yHVijT-R7fgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-19 18:03:33
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 12:39:31
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 08:39:26.170265 2026] [security2:error] [pid 11279:tid 11279] [client 209.172.2.130:32918] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgegourmet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgegourmet.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajU4fkTmidNQA3CTFr3JUwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
stinpriza
2026-06-19 11:12:03
(3 days ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 10:44:27
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 209.172.2.130 (host130.securelyhosted.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 06:44:20.250538 2026] [security2:error] [pid 23175:tid 23175] [client 209.172.2.130:47712] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tradersworldmarket.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tradersworldmarket.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajUdhP7A_r2kDdcLNBfzBQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-19 05:32:03
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1257
Exploited Host
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-06-19 04:12:16
(3 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ซ๐ท
tilellit.pro
2026-06-19 02:24:09
(3 days ago)
Fail2Ban banned 209.172.2.130 for security violations in jail wp-armour. Log: 2026/06/19 02:24:09 [e ...
show more
Fail2Ban banned 209.172.2.130 for security violations in jail wp-armour. Log: 2026/06/19 02:24:09 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 209.172.2.130 | Target: wplogin" , client: 209.172.2.130, server: [REDACTED], request: "POST /wp-login.php HTTP/2.0", upstream: [REDACTED], host: [REDACTED], referrer: "https://espsformacion.com/wp-login.php"
...
show less
Web Spam