๐ซ๐ท
tecnicorioja
2026-09-21 22:00:20
(4 days ago)
POST /xmlrpc.php [21/Sep/2026:18:38:30
Brute-Force
Web App Attack
Anonymous
2026-09-21 02:30:04
(5 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 19:44:55
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-add ...
show more
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:44:47.850279 2026] [security2:error] [pid 18061:tid 18061] [client 217.169.104.209:42644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lightbender.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lightbender.net"] [uri "/wp-json/wp/v2/users"] [unique_id "arA3r0DT6ZA67X68jdsgkgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-20 15:23:08
(5 days ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:33:28
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-add ...
show more
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:33:21.669378 2026] [security2:error] [pid 756:tid 756] [client 217.169.104.209:40912] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sizefinder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sizefinder.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq_Skekd9SYhefBcrBoWgAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-19 22:19:36
(6 days ago)
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-19 19:02:33
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ช๐ธ
robotstxt
2026-09-19 18:46:31
(6 days ago)
217.169.104.209 - - [19/Sep/2026:18:41:38 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 ...
show more
217.169.104.209 - - [19/Sep/2026:18:41:38 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0" "-" edge="217.169.104.209"
217.169.104.209 - - [19/Sep/2026:18:41:39 +0000] "GET /?author=3 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" "-" edge="217.169.104.209"
217.169.104.209 - - [19/Sep/2026:18:41:40 +0000] "GET /?author=4 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0" "-" edge="217.169.104.209"
217.169.104.209 - - [19/Sep/2026:18:41:40 +0000] "GET /?author=5 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" edge="217.169.104.209"
217.169.104.209 - - [19/Sep/2026:18:45:59 +0000] "GET /?author=6 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:82.0) Gecko/20100101 Firefox/82.0" "-" edge="217.169.104.209"
...
show less
Web App Attack
๐ง๐ช
taivas.nl
2026-09-19 16:32:10
(6 days ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-19 12:27:14
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-add ...
show more
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:27:09.351299 2026] [security2:error] [pid 11948:tid 11948] [client 217.169.104.209:53662] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ecruhairsalon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ecruhairsalon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5_nZykl03NX8IIMMDl8AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-19 12:03:08
(6 days ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 217.169.104.209 (IT/Italy/hostx.goblin ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 217.169.104.209 (IT/Italy/hostx.goblin.it): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-19 11:45:42
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-add ...
show more
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:45:35.469274 2026] [security2:error] [pid 6216:tid 6216] [client 217.169.104.209:40816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||agrollum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "agrollum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq513yGiFYMNvqjQpEgQ7QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:42:47
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-add ...
show more
(mod_security) mod_security (id:225170) triggered by 217.169.104.209 (209.128-255.104.169.217.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:42:42.479005 2026] [security2:error] [pid 2222:tid 2237] [client 217.169.104.209:51062] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||culturallyyours.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "culturallyyours.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5nIo_re4sQsOvrYkTu0AAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-19 09:56:35
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
SpaceHost-Server
2026-09-18 22:18:59
(1 week ago)
Brute-Force
Web App Attack