๐บ๐ธ
avgsmoe
2026-06-06 19:01:07
(1 day ago)
REPEAT offender. Observed 1654 times.
Port Scan
Brute-Force
๐บ๐ธ
avgsmoe
2026-06-04 19:37:59
(2 days ago)
REPEAT offender. Observed 1622 times.
Port Scan
Brute-Force
๐บ๐ธ
avgsmoe
2026-05-31 01:01:06
(1 week ago)
CROWDSEC offender. Observed 1556 times.
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
avgsmoe
2026-05-29 19:01:09
(1 week ago)
CROWDSEC offender. Observed 1419 times.
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
avgsmoe
2026-05-24 17:00:12
(2 weeks ago)
REPEAT offender. Observed 1026 times.
Port Scan
Brute-Force
๐บ๐ธ
avgsmoe
2026-05-22 17:00:11
(2 weeks ago)
CROWDSEC offender. Observed 793 times.
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 14:32:51
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 5.9.79.124 (panel555.harmondns.net): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 5.9.79.124 (panel555.harmondns.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 10:32:44.354538 2026] [security2:error] [pid 849:tid 896] [client 5.9.79.124:56430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||luxury.property-management-companies-chicago.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "luxury.property-management-companies-chicago.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ag8XjN2iEsmZ56-rO1O2XQAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-21 04:05:34
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
avgsmoe
2026-05-20 01:01:03
(2 weeks ago)
CROWDSEC offender. Observed 653 times.
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-05-18 17:50:08
(2 weeks ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 5.9.79.124 (DE/Germany/panel555.harmondns.net ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 5.9.79.124 (DE/Germany/panel555.harmondns.net): 1 in the last 3600 secs (0-197)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-18 08:21:01
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 5.9.79.124 (panel555.harmondns.net): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 5.9.79.124 (panel555.harmondns.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 04:20:54.152339 2026] [security2:error] [pid 12462:tid 12462] [client 5.9.79.124:44212] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||slattery-law.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "slattery-law.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agrL5kGAindALMVFfwUQRgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
avgsmoe
2026-05-18 07:00:37
(2 weeks ago)
REPEAT offender. Observed 473 times.
Port Scan
Brute-Force
๐ฉ๐ช
london2038.com
2026-05-16 09:14:38
(3 weeks ago)
Attacking WordPress
5.9.79.124 - - [16/May/2026:11:14:34 +0200] "POST /wp-login.php HTTP/2.0" 503 19 ...
show more
Attacking WordPress
5.9.79.124 - - [16/May/2026:11:14:34 +0200] "POST /wp-login.php HTTP/2.0" 503 19289 "https://<REDACTED>/wp-login.php" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 14:34:17
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 5.9.79.124 (panel555.harmondns.net): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 5.9.79.124 (panel555.harmondns.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 10:34:11.533436 2026] [security2:error] [pid 15294:tid 15388] [client 5.9.79.124:35756] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||darkestmoonart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "darkestmoonart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agcu43COxJehEpFsrrlH5QAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-05-14 16:27:54
(3 weeks ago)
(wordpress) Failed wordpress login from 5.9.79.124 (DE/Germany/Saxony/Falkenstein/panel555.harmondns ...
show more
(wordpress) Failed wordpress login from 5.9.79.124 (DE/Germany/Saxony/Falkenstein/panel555.harmondns.net/[redacted]): (CF_ENABLE)
show less
Brute-Force