๐ฉ๐ช
EGP Abuse Dept
2026-05-26 03:10:17
(3 months ago)
Scanning for web/db/file exploits on www.horitex.nl
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-19 12:47:23
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 217.28.137.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 217.28.137.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 08:47:16.908935 2026] [security2:error] [pid 28541:tid 28550] [client 217.28.137.120:41911] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||howlerrock.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "howlerrock.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agxb1E3b1aEJXxHnBhunZQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 21:15:15
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 217.28.137.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 217.28.137.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 17:15:11.556836 2026] [security2:error] [pid 6320:tid 6343] [client 217.28.137.120:43675] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.howlerrock.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.howlerrock.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acmWX9lbJZZkgCFXL-A3EQAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-03-13 01:55:16
(6 months ago)
217.28.137.120 - [13/Mar/2026:03:55:11 +0200] "POST /wp-login.php?action=lostpassword HTTP/1.1" 200 ...
show more
217.28.137.120 - [13/Mar/2026:03:55:11 +0200] "POST /wp-login.php?action=lostpassword HTTP/1.1" 200 1322 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Firefox/115.0" "2.46"
217.28.137.120 - [13/Mar/2026:03:55:12 +0200] "POST /wp-login.php?action=lostpassword HTTP/1.1" 200 1322 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Firefox/115.0" "2.46"
217.28.137.120 - [13/Mar/2026:03:55:13 +0200] "POST /wp-login.php?action=lostpassword HTTP/1.1" 200 1320 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Firefox/115.0" "2.46"
217.28.137.120 - [13/Mar/2026:03:55:14 +0200] "POST /wp-login.php?action=lostpassword HTTP/1.1" 200 1321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Firefox/115.0" "2.46"
217.28.137.120 - [13/Mar/2026:03:55:16 +0200] "POST /wp-login.php?action=lostpassword HTTP/1.1" 200 1321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Firefox/115.0" "2.46"
...
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-03-08 00:46:54
(6 months ago)
(wordpress) Failed wordpress login from 217.28.137.120 (US/United States/California/Santa Clara/-/[r ...
show more
(wordpress) Failed wordpress login from 217.28.137.120 (US/United States/California/Santa Clara/-/[redacted])
show less
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-03-04 18:41:13
(6 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฎ๐น
VHosting
2026-03-03 13:25:07
(6 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 00:32:48
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 217.28.137.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 217.28.137.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 19:32:42.440787 2026] [security2:error] [pid 32185:tid 32185] [client 217.28.137.120:41611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.hawarcenter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.hawarcenter.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaYsKl-2uAJW-IK8YusRswAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-02-19 16:41:35
(7 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-02-19 16:22:48
(7 months ago)
(wordpress) Failed wordpress login from 217.28.137.120 (US/United States/California/Santa Clara/-/[r ...
show more
(wordpress) Failed wordpress login from 217.28.137.120 (US/United States/California/Santa Clara/-/[redacted])
show less
Brute-Force