π©πͺ
iNetWorker
2026-06-28 12:18:38
(51 minutes ago)
trolling for resource vulnerabilities
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-28 11:59:29
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 60.234.77.227 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 60.234.77.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 07:59:23.836796 2026] [security2:error] [pid 21075:tid 21075] [client 60.234.77.227:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "southernbroadcast.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akEMm-TTO3qW7FCor29TmgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-28 11:40:03
(1 hour ago)
Web App Attack, Hacking
Hacking
Web App Attack
π¦πΊ
paulshipley.com.au
2026-06-28 11:33:31
(1 hour ago)
dance4fitness.com.au:443 60.234.77.227 - - [28/Jun/2026:21:33:28 +1000] "GET /wordpress/xmlrpc.php H ...
show more
dance4fitness.com.au:443 60.234.77.227 - - [28/Jun/2026:21:33:28 +1000] "GET /wordpress/xmlrpc.php HTTP/1.1" 404 69396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
π§πͺ
taivas.nl
2026-06-28 11:32:12
(1 hour ago)
Bad_requests
Bad Web Bot
π¨π¦
polycoda
2026-06-28 11:02:10
(2 hours ago)
π Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack
πΊπΈ
Penny Packer
2026-06-28 10:43:56
(2 hours ago)
Fail2Ban apache-tripwires
Web App Attack
πΊπΈ
Starburst SysOp Team
2026-06-28 10:43:47
(2 hours ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 227.77.234.60.rbl.malwa ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 227.77.234.60.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
πΊπΈ
wordpresshosting.solutions
2026-06-28 10:33:39
(2 hours ago)
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 60.234.77.227 - - [28/Jun/2026: ...
show more
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 60.234.77.227 - - [28/Jun/2026:10:33:24 +0000] "GET /wp-json/wp/v2/users?per_page=100&_fields=id,slug,name,link,roles HTTP/1.1" 401 5905 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
60.234.77.227 - - [28/Jun/2026:10:33:39 +0000] "GET /wp-json/wp/v2/users?per_page=100&orderby=id&order=desc&_fields=id,slug HTTP/1.1" 401 5905 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
π©πͺ
BlueWire Hosting
2026-06-28 10:29:40
(2 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
πΊπΈ
CollideTech
2026-06-28 10:28:12
(2 hours ago)
probing for vulnerabilities
Web App Attack
πΊπΈ
xxkodedxx
2026-06-28 09:54:39
(3 hours ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get in 10m window.
Active: 09:53:39 UTC
Volume: 1 honeypot probe(s)
Bait taken: /wp-json/elementor/v1/globals
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
π¦πΊ
paulshipley.com.au
2026-06-28 09:37:14
(3 hours ago)
angleseaarthouse.com.au:443 60.234.77.227 - - [28/Jun/2026:19:37:12 +1000] "GET /?author=4&feed=rss2 ...
show more
angleseaarthouse.com.au:443 60.234.77.227 - - [28/Jun/2026:19:37:12 +1000] "GET /?author=4&feed=rss2 HTTP/1.1" 404 188836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
π©πͺ
big-cloud.nl
2026-06-28 09:28:20
(3 hours ago)
Try to access /xmlrpc.php
Web App Attack
π©πͺ
FeG Deutschland
2026-06-28 09:18:24
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack