πΊπΈ
TPI-Abuse
2026-09-20 13:45:40
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:45:32.580214 2026] [security2:error] [pid 31819:tid 31819] [client 63.249.93.208:51982] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||twogocamping.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "twogocamping.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq_jfArGPIAKfe8LqDaN_AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-20 08:31:31
(6 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: / (+1 more) | query: author=1 (+1 more) | 2026-09-20 08:31 UTC
show less
Hacking
Web App Attack
π²π½
octageeks.com
2026-09-20 04:22:20
(6 days ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
π©πͺ
ger-stg-sifi1
2026-09-19 21:09:47
(6 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 17:28:56
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:28:51.560601 2026] [security2:error] [pid 7528:tid 7528] [client 63.249.93.208:33060] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.levijoneslegal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.levijoneslegal.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7GU_8ItbkyYxTHad5WdQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-19 15:22:54
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π«π·
masterguru
2026-09-19 15:19:06
(1 week ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
πΊπΈ
TPI-Abuse
2026-09-19 14:38:38
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 10:38:33.420873 2026] [security2:error] [pid 6502:tid 6502] [client 63.249.93.208:46020] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gvimmobilier.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gvimmobilier.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6eaaDtWPVBdGiX3yfj_QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 14:00:31
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 10:00:23.652632 2026] [security2:error] [pid 18434:tid 18434] [client 63.249.93.208:57194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dennisangellismusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dennisangellismusic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6Vd13RB94vAgBuYLtYhQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-19 12:21:11
(1 week ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
πΊπΈ
TPI-Abuse
2026-09-19 12:05:58
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 63.249.93.208 (host8.cruzio.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:05:50.392297 2026] [security2:error] [pid 1390096:tid 1390096] [client 63.249.93.208:40194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||janyoors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "janyoors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq56nogL95sjjdWrrcg_uwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2026-09-09 19:51:00
(2 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
π―π΅
ki3
2026-09-09 10:25:14
(2 weeks ago)
Fail2Ban: Web App Attacks and Forum Spam 63.249.93.208 1788949513.0(JST)
Web Spam
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-09 00:22:10
(2 weeks ago)
Asking over plain http and never following the redirect served β a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served β a crawler that reads nothing it asks for | method: GET | path: /wp-login.php | 2026-09-09 00:22 UTC
show less
Bad Web Bot
πΊπΈ
Penny Packer
2026-09-08 16:24:47
(2 weeks ago)
Fail2Ban apache-tripwires
Web App Attack