๐บ๐ธ
1cyb3rpunk
2026-09-23 22:17:56
(1 hour ago)
Coordinated campaign CMP-1789954617-135: 12 IPs sharing an attack fingerprint (wordpress_xmlrpc). Ob ...
show more
Coordinated campaign CMP-1789954617-135: 12 IPs sharing an attack fingerprint (wordpress_xmlrpc). Observed on sectrace.org honeypot surface.
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-09-22 23:22:45
(1 day ago)
WordPress login attempt
Brute-Force
Anonymous
2026-09-21 17:50:52
(2 days ago)
Blocked by web application firewall: automated malicious HTTP requests (WordPress xmlrpc.php / wp-lo ...
show more
Blocked by web application firewall: automated malicious HTTP requests (WordPress xmlrpc.php / wp-login brute-force and admin-panel scanning). Distributed botnet / automated tooling. No legitimate use.
show less
Brute-Force
Web App Attack
๐บ๐ธ
LSPCCU
2026-09-21 16:37:21
(2 days ago)
TSEC Honeypot Network report. Threat score: 81/100. Categories: Port Scan, Hacking, Brute-Force, Web ...
show more
TSEC Honeypot Network report. Threat score: 81/100. Categories: Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: galah. Context: 39.100.88.232 classified as automated brute-force attacker targeting SSH/Telnet credentials (high confidence).
show less
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
Anonymous
2026-09-21 10:15:04
(2 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
1cyb3rpunk
2026-09-21 04:51:02
(2 days ago)
Coordinated campaign CMP-1789954617-135: 8 IPs sharing an attack fingerprint (wordpress_xmlrpc). Obs ...
show more
Coordinated campaign CMP-1789954617-135: 8 IPs sharing an attack fingerprint (wordpress_xmlrpc). Observed on sectrace.org honeypot surface.
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-21 04:23:12
(2 days ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 18:53:57
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:53:51.685024 2026] [security2:error] [pid 11984:tid 11984] [client 39.100.88.232:58554] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.souldata.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.souldata.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arArv3dw_qrO_Unqew5iPwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 08:08:45
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 04:08:37.597731 2026] [security2:error] [pid 29050:tid 29143] [client 39.100.88.232:44014] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arizonasolutionsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arizonasolutionsgroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq-UhQi-4RFMMdrhBRcGFgAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 05:58:36
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 01:58:32.595368 2026] [security2:error] [pid 27607:tid 27702] [client 39.100.88.232:48388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.brucejoell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.brucejoell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq92CPWAii7leus2fHCOUQAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 18:11:30
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:11:24.107254 2026] [security2:error] [pid 16422:tid 16422] [client 39.100.88.232:42834] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.canebrakes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.canebrakes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7QTPVyQ1Y1ssCrg3W70AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 14:02:46
(4 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 12:05:49
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 39.100.88.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:05:41.593780 2026] [security2:error] [pid 31253:tid 31253] [client 39.100.88.232:47044] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||genesis-castle.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "genesis-castle.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq56lc4GAGdJDvTbK9NOSAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 11:02:57
(4 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐ช๐ธ
robotstxt
2026-09-19 10:42:31
(4 days ago)
39.100.88.232 - - [19/Sep/2026:10:41:35 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 ( ...
show more
39.100.88.232 - - [19/Sep/2026:10:41:35 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:50.0) Gecko/20100101 Firefox/50.0" "-" edge="39.100.88.232"
39.100.88.232 - - [19/Sep/2026:10:41:39 +0000] "GET /?author=3 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0" "-" edge="39.100.88.232"
39.100.88.232 - - [19/Sep/2026:10:41:41 +0000] "GET /?author=4 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:82.0) Gecko/20100101 Firefox/82.0" "-" edge="39.100.88.232"
39.100.88.232 - - [19/Sep/2026:10:41:45 +0000] "GET /?author=5 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:63.0) Gecko/20100101 Firefox/63.0" "-" edge="39.100.88.232"
39.100.88.232 - - [19/Sep/2026:10:41:46 +0000] "GET /?author=6 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0" "-" edge="39.100.88.232"
...
show less
Web App Attack