Anonymous
2026-05-12 07:43:17
(3 weeks ago)
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports ...
show more
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:42:37 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:42:37 +0000] "GET /wp-admin/ HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:42:38 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:43:12 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:43:12 +0000] "GET /xmlrpc.php HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 07:24:04
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 03:23:58.095006 2026] [security2:error] [pid 3072:tid 3178] [client 38.95.35.74:54746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||topo.switchbl8.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "topo.switchbl8.nl"] [uri "/wp-json/wp/v2/users"] [unique_id "agLVjk7geZ43qI1tC01YcgAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 07:12:51
(3 weeks ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 38.95.35.74 (US/United States/-)
Brute-Force
Anonymous
2026-05-12 07:12:44
(3 weeks ago)
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports ...
show more
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:12:24 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:12:25 +0000] "GET /wp-admin/ HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:12:25 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:12:43 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:07:12:43 +0000] "GET /xmlrpc.php HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 07:04:28
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 03:04:22.566243 2026] [security2:error] [pid 22121:tid 22121] [client 38.95.35.74:33890] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||edgecomix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "edgecomix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLQ9itl9RuTJpOyw5tTBAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 06:47:41
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 02:47:34.644007 2026] [security2:error] [pid 7395:tid 7395] [client 38.95.35.74:52186] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sutherlandyogastudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sutherlandyogastudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLNBsaKssWVoetjPOrGjAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 06:44:52
(3 weeks ago)
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports ...
show more
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:43:55 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:43:57 +0000] "GET /wp-admin/ HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:43:57 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:44:47 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:44:47 +0000] "GET /xmlrpc.php HTTP/1.1"
show less
Port Scan
๐จ๐ฟ
plzenskypruvodce.cz
2026-05-12 06:32:41
(3 weeks ago)
2026-05-12T08:32:39.997830+02:00 web wordpress(varhanykolin.cz)[2584171]: Immediately block connecti ...
show more
2026-05-12T08:32:39.997830+02:00 web wordpress(varhanykolin.cz)[2584171]: Immediately block connections from 38.95.35.74
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-12 06:30:54
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 02:30:50.391913 2026] [security2:error] [pid 21348:tid 21348] [client 38.95.35.74:53984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fundingangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fundingangelinvestors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLJGlnweGABOf0uh2JkVQAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 06:16:34
(3 weeks ago)
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports ...
show more
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:16:28 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:16:28 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:16:28 +0000] "GET /wp-admin/ HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:16:33 +0000] "GET /wp-admin/ HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:06:16:33 +0000] "GET /wp-login.php HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 06:15:34
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 38.95.35.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 02:15:27.001001 2026] [security2:error] [pid 11207:tid 11207] [client 38.95.35.74:60074] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iee-usa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iee-usa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLFfg9_JXkgHTXz0DcObgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 06:10:59
(3 weeks ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 38.95.35.74 (US/United States/-)
Brute-Force
๐ซ๐ท
Kimax
2026-05-12 06:07:48
(3 weeks ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ง๐ช
taivas.nl
2026-05-12 06:02:11
(3 weeks ago)
Bad_requests
Bad Web Bot
Anonymous
2026-05-12 05:50:56
(3 weeks ago)
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports ...
show more
(caddyscan) Scanner path probe from 38.95.35.74 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:05:49:56 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:05:49:56 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:05:49:56 +0000] "GET /wp-admin/ HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:05:50:53 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 38.95.35.74 - - [12/May/2026:05:50:53 +0000] "GET /xmlrpc.php HTTP/1.1"
show less
Port Scan