🇬🇧
gigatech
2026-09-14 11:55:08
(1 hour ago)
Webserver Probing
Web App Attack
🇩🇪
FeG Deutschland
2026-09-14 07:54:35
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇪🇸
masterguru
2026-09-14 00:21:57
(12 hours ago)
*Port Scan* detected from 59.30.43.16 (KR/South Korea/-). 11 hits in the last 90 seconds (0-122)
Port Scan
🇺🇸
lostswordfish.com
2026-09-13 21:16:03
(15 hours ago)
Wordfence waf block on fairregistry
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-13 21:12:26
(15 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇲🇹
Malta
2026-09-13 17:12:20
(19 hours ago)
59.30.43.16 - - [13/Sep/2026:19:12:20 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
59.30.43.16 - - [13/Sep/2026:19:12:20 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-12 19:38:31
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 15:38:26.050326 2026] [security2:error] [pid 16903:tid 16903] [client 59.30.43.16:37886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drwolberg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drwolberg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqWqMgvWJAMGE9pbBJLi2wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-11 08:17:53
(3 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 14:10:17
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 10:10:08.950029 2026] [security2:error] [pid 12340:tid 12340] [client 59.30.43.16:37022] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desdier.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desdier.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqK6QADP8a2AHgh33qvagwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 05:44:30
(5 days ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026- ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026-09-09 05:44 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:31:50
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:31:46.437591 2026] [security2:error] [pid 12359:tid 12359] [client 59.30.43.16:50980] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oliverhardy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oliverhardy.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBUkvW-psS7manJXpmMewAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:33:33
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:33:26.733851 2026] [security2:error] [pid 3100:tid 3107] [client 59.30.43.16:49040] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dontbeajerklikeyourwork.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dontbeajerklikeyourwork.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBG5vsZ34QsbkhdaXvsRwAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:46:13
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:46:08.574741 2026] [security2:error] [pid 10095:tid 10095] [client 59.30.43.16:38690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||smartradios.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "smartradios.info"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAfsIQIDOStG5W3eiIQFQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:21:02
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:20:54.044159 2026] [security2:error] [pid 4287:tid 4306] [client 59.30.43.16:42706] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.kennedyfineartphotography.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.kennedyfineartphotography.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_vllTvHSOgSPFX0-_mawAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:04:37
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 59.30.43.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:04:33.129705 2026] [security2:error] [pid 19874:tid 19874] [client 59.30.43.16:60420] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lambert-heating-and-air.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_PoX_fnZWwYtaVb2eNvQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack