๐บ๐ธ
cwytech
2026-09-23 05:47:30
(1 week ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 04:32:28
(1 week ago)
2026-09-23T04:32:28.219784+00:00 instance-20260804-1025 wordpress(cazseguros.com)[1068094]: XML-RPC ...
show more
2026-09-23T04:32:28.219784+00:00 instance-20260804-1025 wordpress(cazseguros.com)[1068094]: XML-RPC authentication attempt for unknown user web_user from 62.171.152.99
...
show less
Web App Attack
Anonymous
2026-09-22 10:49:05
(1 week ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
QT
2026-09-22 04:15:56
(1 week ago)
Unauthorised WordPress admin login attempted at 2026-09-22 14:15:47 +1000
Web App Attack
Anonymous
2026-09-21 22:45:02
(1 week ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
lostswordfish.com
2026-09-21 04:46:04
(1 week ago)
Wordfence waf block on robdarnell
Web App Attack
Anonymous
2026-09-21 03:00:50
(1 week ago)
WordPress Brute Force
Brute-Force
๐ช๐ธ
SweetHoneyPress
2026-09-21 01:42:57
(1 week ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=1384356 | UA: Mozilla/5.0 (Windows NT 10.0; Win64 ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=1384356 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
Anonymous
2026-09-20 22:52:56
(1 week ago)
Web probing (1 hits in 24h) on helenehoenjet.nl: sensitive-path scans and/or 404 bursts. Reported by ...
show more
Web probing (1 hits in 24h) on helenehoenjet.nl: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 03:05:54
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.171.152.99 (vmi2490483.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 62.171.152.99 (vmi2490483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 23:05:51.044524 2026] [security2:error] [pid 13580:tid 13580] [client 62.171.152.99:38656] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "johncyphers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9Nj6NSz1n4GFeCWFxh2wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-19 20:27:27
(1 week ago)
62.171.152.99 - - [19/Sep/2026:20:26:25 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 ( ...
show more
62.171.152.99 - - [19/Sep/2026:20:26:25 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0" "-" edge="62.171.152.99"
62.171.152.99 - - [19/Sep/2026:20:26:26 +0000] "GET /?author=3 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0" "-" edge="62.171.152.99"
62.171.152.99 - - [19/Sep/2026:20:26:27 +0000] "GET /?author=4 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0" "-" edge="62.171.152.99"
62.171.152.99 - - [19/Sep/2026:20:26:28 +0000] "GET /?author=5 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" edge="62.171.152.99"
62.171.152.99 - - [19/Sep/2026:20:26:29 +0000] "GET /?author=6 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:43.0) Gecko/20100101 Firefox/43.0" "-" edge="62.171.152.99"
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-19 19:32:57
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 15:46:03
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.171.152.99 (vmi2490483.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 62.171.152.99 (vmi2490483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 11:45:55.564516 2026] [security2:error] [pid 9529:tid 9529] [client 62.171.152.99:49176] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||scrunchiebuttbikinis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "scrunchiebuttbikinis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6uMy_wbAGE3_jwuGqEnAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 13:46:15
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.171.152.99 (vmi2490483.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 62.171.152.99 (vmi2490483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 09:46:06.989850 2026] [security2:error] [pid 25862:tid 25862] [client 62.171.152.99:37532] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ohiohca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ohiohca.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6SHrCT2gzrnqi4vba3twAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:47:17
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.171.152.99 (vmi2490483.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 62.171.152.99 (vmi2490483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:47:14.265169 2026] [security2:error] [pid 27754:tid 27754] [client 62.171.152.99:45136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iplayriichi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iplayriichi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq52QnYSybfOvmG4Z9LwBAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack