๐บ๐ธ
TPI-Abuse
2026-10-08 05:57:02
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:56:57.227691 2026] [security2:error] [pid 26372:tid 26372] [client 217.160.240.109:44558] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||christineaholtz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "christineaholtz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ascwqcPQMIrI1mLKmNM2CgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-07 19:02:03
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 15:58:57
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:58:51.069225 2026] [security2:error] [pid 18369:tid 18369] [client 217.160.240.109:55026] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||maidsinmalta.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "maidsinmalta.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asZsO5gRz6mJn5sYrjj3OwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:15:09
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:15:02.815954 2026] [security2:error] [pid 32400:tid 32400] [client 217.160.240.109:59332] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brbcash.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brbcash.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asY3xuZW69oyAef0uWd1-AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Security_Whaller
2026-10-07 11:04:41
(3 days ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:42:14
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:42:09.426675 2026] [security2:error] [pid 2742136:tid 2742187] [client 217.160.240.109:44336] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||travelusa.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "travelusa.us"] [uri "/wp-json/wp/v2/users"] [unique_id "asVrMTX4BjLQe1YfbNsQBwAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:40:07
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:40:00.394028 2026] [security2:error] [pid 17581:tid 17581] [client 217.160.240.109:43024] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||majesticsolutions.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "majesticsolutions.co"] [uri "/wp-json/wp/v2/users"] [unique_id "asVcoPSmgXvyUYizb5H3HwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:16:38
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:16:31.925796 2026] [security2:error] [pid 6766:tid 6766] [client 217.160.240.109:45782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tonydelov.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tonydelov.net"] [uri "/wp-json/wp/v2/users"] [unique_id "asVXH5TtAwLAVpb-NMJJPAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 19:21:02
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 15:20:57.913255 2026] [security2:error] [pid 30700:tid 30700] [client 217.160.240.109:60348] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||airdriedrivingschool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "airdriedrivingschool.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asVKGU6X-bIKiybNfpxowAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:45:49
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:45:43.742850 2026] [security2:error] [pid 31620:tid 31620] [client 217.160.240.109:32784] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||timetemple.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "timetemple.org"] [uri "/wp-json/wp/v2/users"] [unique_id "asUlt5xcIpsupgv4zPFA5AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:13:02
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.240.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:12:56.624597 2026] [security2:error] [pid 13417:tid 13417] [client 217.160.240.109:37308] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||creationorevolution.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "creationorevolution.net"] [uri "/wp-json/wp/v2/users"] [unique_id "asUP-OeIZtTLIEy1heEmmAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
numberstorm
2026-10-04 21:49:22
(6 days ago)
Honeypot trap triggered: unsolicited TCP connection(s) to unused port(s) 23 on a host running no suc ...
show more
Honeypot trap triggered: unsolicited TCP connection(s) to unused port(s) 23 on a host running no such service. There is no legitimate reason to connect to these ports.
Observed 1 connection(s) from 2026-10-04T20:28:03Z to 2026-10-04T20:28:03Z UTC.
2026-10-04T20:28:03Z tcp/23 data: GET / HTTP/1.2 Accept-Encoding: gzip, deflate, br Accept-L...
Connection was blocked automatically at the firewall. Reported by an automated honeypot.
show less
Port Scan
Hacking
Brute-Force
IoT Targeted
๐ฎ๐ฉ
xveil
2026-10-02 21:44:58
(1 week ago)
2026-10-03T04:44:56.489638 mail-honeypot postfix/submission/smtpd[23480]: warning: unknown[217.160.2 ...
show more
2026-10-03T04:44:56.489638 mail-honeypot postfix/submission/smtpd[23480]: warning: unknown[217.160.240.109]: SASL PLAIN authentication failed: authentication failure
...
show less
Brute-Force
๐ฉ๐ช
LRob
2026-10-02 20:45:07
(1 week ago)
Vulnerability scanning | method: GET | path: /wp-json/ | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x6 ...
show more
Vulnerability scanning | method: GET | path: /wp-json/ | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-02 13:53:13
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack