๐ฒ๐ฝ
octageeks.com
2026-08-11 04:09:45
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-08-10 19:58:07
(3 weeks ago)
44.220.91.223 - - [11/Aug/2026:01:28:06 +0530] "GET /readme.html HTTP/2.0" 200 3029 "-" "Mozilla/5.0 ...
show more
44.220.91.223 - - [11/Aug/2026:01:28:06 +0530] "GET /readme.html HTTP/2.0" 200 3029 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
LRob
2026-08-10 15:58:54
(3 weeks ago)
WordPress REST-API user enumeration (probing CVE-2017-5487 to harvest usernames) | req: /wp-json/wp/ ...
show more
WordPress REST-API user enumeration (probing CVE-2017-5487 to harvest usernames) | req: /wp-json/wp/v2/users?_jsonp=callback&per_page=100&_fields=id,slug | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐ฉ๐ช
YF
2026-08-10 15:00:13
(3 weeks ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
xxkodedxx
2026-08-10 14:11:20
(3 weeks ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 14:10:27 UTC
Volume: 1 honeypot probe(s)
Bait taken: /wp-json/wp/v2/users?_fields=slug&per_page=100&page=1
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 13:52:48
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 44.220.91.223 (ec2-44-220-91-223.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 44.220.91.223 (ec2-44-220-91-223.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 09:52:42.185117 2026] [security2:error] [pid 542453:tid 542453] [client 44.220.91.223:42726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rotentendales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rotentendales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "annXqvsirlCsmFIhEDHufQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-10 12:05:19
(3 weeks ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-10 12:03:57
(3 weeks ago)
cloudlinux2 fail2ban: 2026-08-10 13:59:17,442 fail2ban.filter [1708]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-10 13:59:17,442 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 44.220.91.223 - 2026-08-10 13:59:17cloudlinux2 fail2ban: 2026-08-10 13:59:57,639 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 106.51.180.12 - 2026-08-10 13:59:57cloudlinux2 fail2ban: 2026-08-10 14:01:00,886 fail2ban.filter [1708]: INFO [recidive] Found 106.51.180.12 - 2026-08-10 14:01:00cloudlinux2 fail2ban: 2026-08-10 14:01:00,609 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 106.51.180.12 - 2026-08-10 14:01:00cloudlinux2 fail2ban: 2026-08-10 14:01:00,880 fail2ban.actions [1708]: NOTICE [plesk-modsecurity] Ban 106.51.180.12cloudlinux2 fail2ban: 2026-08-10 14:01:56,204 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 194.68.17.43 - 2026-08-10 14:01:56cloudlinux2 fail2ban: 2026-08-10 14:01:51,384 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 15.188.152.96 - 2026-08-10 14:01:51cloudlinux2 fail2ban: 2026-08
show less
Brute-Force
Anonymous
2026-08-10 11:40:07
(3 weeks ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
stinpriza
2026-08-10 11:27:57
(3 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 10:57:18
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 44.220.91.223 (ec2-44-220-91-223.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 44.220.91.223 (ec2-44-220-91-223.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 06:57:14.646959 2026] [security2:error] [pid 278887:tid 278887] [client 44.220.91.223:36508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lahamradio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anmuigVneHsRvDdyu9qsVQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 10:31:21
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 44.220.91.223 (ec2-44-220-91-223.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 44.220.91.223 (ec2-44-220-91-223.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 06:31:17.145803 2026] [security2:error] [pid 22062:tid 22062] [client 44.220.91.223:54356] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||garantaconsulting.internetnameregistration.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "garantaconsulting.internetnameregistration.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anmodbJNj_cpSUebQ8mruwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 09:57:49
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 44.220.91.223 (ec2-44-220-91-223.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 44.220.91.223 (ec2-44-220-91-223.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 05:57:44.076637 2026] [security2:error] [pid 3804249:tid 3804249] [client 44.220.91.223:49684] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||neconebooks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "neconebooks.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "anmgmKc1vhFXSyUyBNdq1gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-10 09:55:03
(3 weeks ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 44.220.91.223 (US/United States/ec2-44-220-91- ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 44.220.91.223 (US/United States/ec2-44-220-91-223.compute-1.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 44.220.91.223 - - [10/Aug/2026:11:54:57 +0200] "GET /wp-json/wp/v2/users?per_page=100&_fields=slug,locale HTTP/2.0" 200 29 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" "-" host=thekna.eu
show less
Port Scan
๐ฉ๐ช
maxpower
2026-08-10 09:30:55
(3 weeks ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 44.220.91.223 (US/United States/ec2-44-220-91- ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 44.220.91.223 (US/United States/ec2-44-220-91-223.compute-1.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 44.220.91.223 - - [10/Aug/2026:11:29:31 +0200] "GET /wp-json/wp/v2/users?_jsonp=callback&per_page=100&_fields=id,slug HTTP/2.0" 200 56 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" "-" host=papertek.it
show less
Port Scan