🇺🇸
TPI-Abuse
2026-09-01 12:11:39
(5 days ago)
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown ...
show more
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:11:34.563010 2026] [security2:error] [pid 6959:tid 6959] [client 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2:65519] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||kh6jim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kh6jim.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apbA9Mmwk5oY_bXik4dlngAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 07:09:35
(6 days ago)
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown ...
show more
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:09:31.238667 2026] [security2:error] [pid 236589:tid 236622] [client 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2:59306] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kettlehill.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apZ6KMfpSwUk1Zhun1luOwAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-31 21:30:24
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.online | URI: /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect= | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-31 16:36:37
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: definitelynotahoneypot.online | URI: /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect= | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 15:58:08
(6 days ago)
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown ...
show more
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:58:05.267612 2026] [security2:error] [pid 442:tid 442] [client 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2:49756] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||kbalan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kbalan.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apWkiGnSNIX5Kg3zQgFpKgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 08:43:35
(1 week ago)
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown ...
show more
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:43:29.808821 2026] [security2:error] [pid 26246:tid 26246] [client 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2:63331] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||kathydumesnilart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kathydumesnilart.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apU-r3hGj-qPxrEzq0joeQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 01:53:42
(1 week ago)
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown ...
show more
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 21:53:35.820171 2026] [security2:error] [pid 5921:tid 5921] [client 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2:49913] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||bostonlog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bostonlog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apTenjydjql_F2GnreS0JAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 20:25:35
(1 week ago)
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown ...
show more
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:25:28.225585 2026] [security2:error] [pid 9688:tid 9688] [client 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2:0] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||bbproductionsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bbproductionsonline.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apSRtbJpbmzLIPrbkrMdJwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-30 17:07:50
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.online | URI: /wp-admin/admin-ajax.php?action=wdpsso_step1&redirect= | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 09:29:14
(1 week ago)
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown ...
show more
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 05:29:07.679570 2026] [security2:error] [pid 6186:tid 6186] [client 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2:55244] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||kaldaragroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kaldaragroup.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apP33oQyJ0mBaL2rufwyZQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 06:17:40
(1 week ago)
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown ...
show more
(mod_security) mod_security (id:243420) triggered by 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 02:17:33.024207 2026] [security2:error] [pid 8067:tid 8067] [client 2402:8780:1063:5e0:cd0c:aab9:6f75:bac2:53134] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||kairoslogammakmur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kairoslogammakmur.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apPK-b284Qwg5XWdPI0UbgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-08-27 01:07:38
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-admin-interface-probing
Web App Attack
Hacking
🇮🇹
VHosting
2026-08-26 16:30:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-08-26 06:15:47
(1 week ago)
Web attack blocked by Wordfence on beeldentuinrolduc.nl (1 hit). Reported by CRMON.
Web App Attack
🇪🇸
alferez
2026-08-25 23:17:36
(1 week ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack