๐ฉ๐ช
AetherFox
2026-09-16 13:47:03
(2 days ago)
AetherFox VoidGuard detected: [Wed Sep 16 13:47:02.118447 2026] [security2:error] [pid 2603176:tid 2 ...
show more
AetherFox VoidGuard detected: [Wed Sep 16 13:47:02.118447 2026] [security2:error] [pid 2603176:tid 2603203] [client 35.187.15.215:60743] [client 35.187.15.215] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 23.88.112.221" against "REMOTE_ADDR" required. [file "/etc/modsecurity/AetherFox.conf"] [line "34"] [id "100053"] [msg "wp-includes access blocked by AetherFox VoidGuard"] [hostname "draconigen.net"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "aqqd1v-yl9ewQkG8XvkkIwAAARE"]
[Wed Sep 16 13:47:02.589171 2026] [security2:error] [pid 2603176:tid 2603205] [client 35.187.15.215:53773] [client 35.187.15.215] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 23.88.112.221" against "REMOTE_ADDR" required. [file "/etc/modsecurity/AetherFox.conf"] [line "34"] [id "100053"] [msg "wp-includes access blocked by AetherFox VoidGuard"] [hostname "draconigen.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "aqqd1v-yl9ewQkG8X
...
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 13:43:15
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 35.187.15.215 (215.15.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 35.187.15.215 (215.15.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:43:09.206951 2026] [security2:error] [pid 6070:tid 6074] [client 35.187.15.215:55920] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dontbeajerklikeyourwork.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dontbeajerklikeyourwork.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqqc7UbnZbJcE5zYwS3otwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-16 13:38:12
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: docker.astropot.tech | URI: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 | BODY: <?xml version="1.0"?><methodCall><methodName>system.multicall</methodName><params><param><value><array><data> <value><struct><member><name>methodName</name><value><string>wp.getUsersBlogs</string></value></member><member><name>params</name><value><array><data><value><array><data><value><string>admin</string></value><valu
show less
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-16 13:37:32
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 18 hits.
show less
Brute-Force
Web App Attack
๐ฉ๐ช
cloudmax
2026-09-16 13:30:37
(2 days ago)
Cloudmax Protect [BOT BLOCK] - Suspicious User-Agent. Possible resource abuse, excessive requests, o ...
show more
Cloudmax Protect [BOT BLOCK] - Suspicious User-Agent. Possible resource abuse, excessive requests, or hacking attempt
show less
Bad Web Bot
๐ฎ๐น
VHosting
2026-09-16 13:30:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:27:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 35.187.15.215 (215.15.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 35.187.15.215 (215.15.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:27:38.888429 2026] [security2:error] [pid 14947:tid 14947] [client 35.187.15.215:59684] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dianamead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dianamead.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqqZSpVai_lDxIN2SBLALAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-16 13:27:29
(2 days ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 13:27:11
(2 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-16 13:27 UTC
show less
Bad Web Bot
๐ง๐ช
taivas.nl
2026-07-04 04:32:32
(2 months ago)
Many_bad_calls
Web App Attack
๐ง๐ช
cmbplf
2026-07-03 16:34:42
(2 months ago)
13.953 requests with url.path //xmlrpc.php
13.789 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-07-03 15:05:27
(2 months ago)
Abuse Detected (18)
Brute-Force
Web App Attack
๐ง๐ช
taivas.nl
2026-07-03 15:02:14
(2 months ago)
Bad_requests
Bad Web Bot
๐ฎ๐น
VHosting
2026-07-03 14:40:05
(2 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 14:39:00
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 35.187.15.215 (215.15.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 35.187.15.215 (215.15.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 10:38:56.664101 2026] [security2:error] [pid 880:tid 880] [client 35.187.15.215:52206] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.verdeprofundo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.verdeprofundo.net"] [uri "/"] [unique_id "akfJgDXnsLFtYeNkKXu31QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack