๐ฉ๐ช
FeG Deutschland
2026-09-16 21:22:33
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ช๐ธ
SweetHoneyPress
2026-09-14 14:49:58
(2 days ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=1355209 | UA: Mozilla/5.0 (X11; Linux x86_64) App ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=1355209 | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
Anonymous
2026-09-14 09:34:26
(2 days ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 07:13:52
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 31.31.31.37 (37.31.31.31.dyn.idknet.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 31.31.31.37 (37.31.31.31.dyn.idknet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:13:46.827198 2026] [security2:error] [pid 24536:tid 24536] [client 31.31.31.37:51600] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tomartsmedia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tomartsmedia.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqZNKlqhFWqEE6VKCxwOjAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-13 02:09:27
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-09-12 04:36:27
(4 days ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-10 16:53:38
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 31.31.31.37 (37.31.31.31.dyn.idknet.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 31.31.31.37 (37.31.31.31.dyn.idknet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:53:33.774592 2026] [security2:error] [pid 1957:tid 1957] [client 31.31.31.37:52802] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||site.ablogisticsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "site.ablogisticsgroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqLgjdsI-7SfLe18hztYewAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 05:09:47
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 31.31.31.37 (37.31.31.31.dyn.idknet.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 31.31.31.37 (37.31.31.31.dyn.idknet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:09:42.515184 2026] [security2:error] [pid 7555:tid 7555] [client 31.31.31.37:48880] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||spacebooger.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "spacebooger.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDqFvKgNIlZY8XD20oEZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-09 04:01:17
(1 week ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 31.31.31.37 (MD/Moldova/37.31.31.31.dyn.idkne ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 31.31.31.37 (MD/Moldova/37.31.31.31.dyn.idknet.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
LRob
2026-09-09 00:17:02
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-09-09 00:17 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-08 22:06:23
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฒ๐น
Malta
2026-09-08 12:20:37
(1 week ago)
31.31.31.37 - - [08/Sep/2026:14:20:37 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
31.31.31.37 - - [08/Sep/2026:14:20:37 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-08 09:56:42
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 31.31.31.37 (37.31.31.31.dyn.idknet.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 31.31.31.37 (37.31.31.31.dyn.idknet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:56:36.780663 2026] [security2:error] [pid 26726:tid 26726] [client 31.31.31.37:37402] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fundingangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fundingangelinvestors.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_b1OTOZkUWBn9lmUHL9QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-07 09:18:51
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
Anonymous
2026-09-06 20:19:32
(1 week ago)
WordPress Brute Force
Brute-Force