๐ซ๐ท
SpaceHost-Server
2026-09-01 22:23:17
(7 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-31 14:52:19
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐ซ๐ท
SpaceHost-Server
2026-08-31 12:37:50
(1 day ago)
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-08-31 11:18:00
(1 day ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-31 11:04:41
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 37.120.207.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 37.120.207.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:04:34.316714 2026] [security2:error] [pid 14278:tid 14278] [client 37.120.207.190:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cloudex.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cloudex.click"] [uri "/wp-json/wp/v2/users/"] [unique_id "apVfwqYOUI_YRX0x3-PHegAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 09:55:10
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 37.120.207.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 37.120.207.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:55:06.662457 2026] [security2:error] [pid 15914:tid 15914] [client 37.120.207.190:49532] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||speedgo.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "speedgo.mx"] [uri "/wp-json/wp/v2/users/"] [unique_id "apVPeuj_liSzmOyX3e_2-QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-08-31 08:39:14
(1 day ago)
CrowdSec at athena Reports Abuse
Web App Attack
Anonymous
2026-08-31 08:38:22
(1 day ago)
Bad Web Bot
๐ฉ๐ช
Melle
2026-08-31 07:26:46
(1 day ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 37.120.207.190 triggered 11 events | De ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 37.120.207.190 triggered 11 events | Detected: 2026-08-31T07:26:45.007701135Z
show less
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-08-31 07:05:19
(1 day ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ฆ๐น
neo72
2026-08-31 06:42:39
(1 day ago)
Detected malicious activity - bulk block
Brute-Force
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-31 06:24:06
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-includes/ (Match: /wp-includes/)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:18:49
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 37.120.207.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 37.120.207.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:18:43.995504 2026] [security2:error] [pid 10185:tid 10185] [client 37.120.207.190:44762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bridgital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bridgital.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "apUcw2bx-2_-OXjAJByXHgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-08-31 06:16:47
(1 day ago)
2026/08/31 06:16:45 [error] 1221355#1221355: *539211024 access forbidden by rule, client: 37.120.207 ...
show more
2026/08/31 06:16:45 [error] 1221355#1221355: *539211024 access forbidden by rule, client: 37.120.207.190, server: bonusnews.org, request: "GET //wp-includes/wlwmanifest.xml HTTP/2.0", host: "bonusnews.org"
2026/08/31 06:16:45 [error] 1221355#1221355: *539211024 access forbidden by rule, client: 37.120.207.190, server: bonusnews.org, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "bonusnews.org"
2026/08/31 06:16:45 [error] 1221355#1221355: *539211024 access forbidden by rule, client: 37.120.207.190, server: bonusnews.org, request: "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0", host: "bonusnews.org"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 05:35:18
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 37.120.207.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 37.120.207.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:35:14.482737 2026] [security2:error] [pid 3381:tid 3381] [client 37.120.207.190:38944] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||glassclublake.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "glassclublake.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "apUSkpxlYwyRealRkqlQrgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack