🇺🇸
TPI-Abuse
2026-08-30 22:15:09
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 18:15:01.820882 2026] [security2:error] [pid 10767:tid 10767] [client 35.239.2.38:22996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||williamfitzsimmons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "williamfitzsimmons.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apSrZT6afdRNGAQA16hZsQAAAAo"], referer: http://williamfitzsimmons.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-08-30 22:03:00
(1 hour ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-30 21:57:47
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 17:57:43.313824 2026] [security2:error] [pid 10771:tid 10771] [client 35.239.2.38:38142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ubuciko.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ubuciko.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apSnV-kdIeFa28hVEbkHEwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 21:06:49
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 17:06:42.071577 2026] [security2:error] [pid 24949:tid 24949] [client 35.239.2.38:39942] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rockinr.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rockinr.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apSbYhqA20TlFPjCUL7oGgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
entangled_mongoose
2026-08-30 20:47:16
(2 hours ago)
Probed /wp-login.php.
Web App Attack
🇺🇸
etu brutus
2026-08-30 20:37:55
(3 hours ago)
35.239.2.38 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 20:28:25
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:28:20.821698 2026] [security2:error] [pid 27326:tid 27349] [client 35.239.2.38:63224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woodamy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woodamy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apSSZNPt5Zi3uuZhwQ_oFgAAABU"], referer: http://woodamy.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
seniorlinuxadmin
2026-08-30 20:19:58
(3 hours ago)
35.239.2.38 - - [30/Aug/2026:07:05:26 +0100] "GET /wp-login.php HTTP/2.0" 404 158 "-" "Mozilla/5.0 ( ...
show more
35.239.2.38 - - [30/Aug/2026:07:05:26 +0100] "GET /wp-login.php HTTP/2.0" 404 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 19:28:31
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:225170) triggered by 35.239.2.38 (38.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:28:24.568018 2026] [security2:error] [pid 26796:tid 26862] [client 35.239.2.38:59658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||asetiadi.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "asetiadi.net"] [uri "/wp-json/wp/v2/users"] [unique_id "apSEWDuR7SzsMAeND2dZCQAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nyt
2026-08-30 18:38:33
(4 hours ago)
WP User Enumeration, WP login POST blocked by WAF
Brute-Force
Web App Attack
🇩🇪
maxpower
2026-08-30 18:37:36
(5 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 35.239.2.38 (US/United States/38.2.239.35.bc.g ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 35.239.2.38 (US/United States/38.2.239.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.239.2.38 - - [30/Aug/2026:20:37:32 +0200] "GET /wp-json/wp/v2/users HTTP/2.0" 200 1748 "http://falone.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0" "-" host=falone.com
show less
Port Scan
🇫🇷
Rom74
2026-08-28 19:38:35
(2 days ago)
2026-08-28T21:38:32.039536+02:00 serveur1 sshd[2867068]: pam_unix(sshd:auth): authentication failure ...
show more
2026-08-28T21:38:32.039536+02:00 serveur1 sshd[2867068]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=35.239.2.38
2026-08-28T21:38:34.692827+02:00 serveur1 sshd[2867068]: Failed password for invalid user rom74 from 35.239.2.38 port 38378 ssh2
...
show less
Brute-Force
SSH
🇩🇪
yvoictra
2026-08-27 09:23:55
(3 days ago)
Bloqueado automáticamente por CrowdSec. Escenario: crowdsecurity/ssh-bf
Brute-Force
SSH
🇺🇸
cwytech
2026-08-27 07:33:36
(3 days ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/tpot-ssh-crit.
Brute-Force
SSH
🇩🇪
wlt-blocker
2026-08-24 07:21:07
(6 days ago)
Illegal port scans
Port Scan