🇩🇪
maxpower
2026-08-23 05:45:27
(1 week ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.123.139 (FI/Finland/static.139.123.238. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.123.139 (FI/Finland/static.139.123.238.62.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 62.238.123.139 - - [23/Aug/2026:07:45:26 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 0 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=matteodinicola.net
show less
Port Scan
🇩🇪
maxpower
2026-08-23 05:03:26
(1 week ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.123.139 (FI/Finland/static.139.123.238. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.123.139 (FI/Finland/static.139.123.238.62.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 62.238.123.139 - - [23/Aug/2026:07:03:24 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 1988 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=egroupadv.it
show less
Port Scan
🇩🇪
maxpower
2026-08-23 02:53:12
(1 week ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.123.139 (FI/Finland/static.139.123.238. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.123.139 (FI/Finland/static.139.123.238.62.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 62.238.123.139 - - [23/Aug/2026:04:53:10 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 783 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=squalettiacademy.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-08-23 02:28:47
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 22:28:41.070896 2026] [security2:error] [pid 30700:tid 30700] [client 62.238.123.139:44332] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||joevallone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "joevallone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aopa2Z0dFVh5mCV65oipSAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 00:55:23
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 20:55:15.569885 2026] [security2:error] [pid 31843:tid 31843] [client 62.238.123.139:21496] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marianozaro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marianozaro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aopE88fnsUz1dpfTVk48LgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 22:01:44
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 18:01:39.352874 2026] [security2:error] [pid 1716:tid 1716] [client 62.238.123.139:35714] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||proyectando.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "proyectando.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoocQ_5zgVwcpEjXcXp6pQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-22 21:40:24
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 21:30:45
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 17:30:40.917285 2026] [security2:error] [pid 3637:tid 3699] [client 62.238.123.139:51434] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atlasrecordssearch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atlasrecordssearch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aooVANDDd--gkXpEPyIhtgAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-22 20:11:30
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 19:53:15
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:53:06.939984 2026] [security2:error] [pid 15990:tid 16011] [client 62.238.123.139:26790] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||captechinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "captechinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aon-IoKHOMuU67pT-5XGFAAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 19:24:46
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:24:39.202994 2026] [security2:error] [pid 7948:tid 7948] [client 62.238.123.139:17364] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||saveourstats.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "saveourstats.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aon3dzZysnsNFIhTIOj4UQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
HandyTreff.de
2026-08-22 16:47:22
(1 week ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -90.57 (Bad < -10 / Very Bad < -20 / ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -90.57 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)
show less
Web App Attack
Bad Web Bot
🇩🇪
maxpower
2026-08-22 15:16:01
(1 week ago)
(PERMBLOCK) 62.238.123.139 (FI/Finland/static.139.123.238.62.clients.your-server.de) has had more th ...
show more
(PERMBLOCK) 62.238.123.139 (FI/Finland/static.139.123.238.62.clients.your-server.de) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
🇦🇺
Bay13
2026-08-22 14:58:46
(1 week ago)
CrowdSec:custom/http-probing
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 14:50:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.123.139 (static.139.123.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:50:18.330741 2026] [security2:error] [pid 5732:tid 5742] [client 62.238.123.139:33052] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brucejoell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brucejoell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aom3KvZvh89aaueW_uCSpgAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack