๐ฒ๐ฝ
octageeks.com
2026-06-08 04:20:42
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ช๐ธ
librebit
2026-06-08 01:21:09
(1 week ago)
Brute force
Brute-Force
๐ฒ๐น
Malta
2026-06-07 17:09:26
(2 weeks ago)
65.254.225.213 - - [07/Jun/2026:19:09:26 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (X11; Linux ...
show more
65.254.225.213 - - [07/Jun/2026:19:09:26 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-07 13:25:15
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-06-07 04:09:37
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ซ๐ท
masterguru
2026-06-07 03:26:52
(2 weeks ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 65.254.225.213 (US/United States/65-254-225-2 ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 65.254.225.213 (US/United States/65-254-225-213.yourhostingaccount.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
FeG Deutschland
2026-06-06 22:49:44
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 01:47:10
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccou ...
show more
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccount.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 21:47:05.208166 2026] [security2:error] [pid 8528:tid 8528] [client 65.254.225.213:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "southernbroadcast.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiN8GSuBR2L5Ddz7-oQV1AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-06-06 01:41:51
(2 weeks ago)
65.254.225.213 - - [05/Jun/2026:19:41:50 -0600] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 ...
show more
65.254.225.213 - - [05/Jun/2026:19:41:50 -0600] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 23:45:56
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccou ...
show more
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccount.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 19:45:48.079702 2026] [security2:error] [pid 23035:tid 23035] [client 65.254.225.213:53748] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wild-goose.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wild-goose.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiNfrLZ_FlXrwd6DlTyHDAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-06-05 21:44:15
(2 weeks ago)
65.254.225.213 - - [05/Jun/2026:23:44:15 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; CrO ...
show more
65.254.225.213 - - [05/Jun/2026:23:44:15 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐ฉ๐ช
Martin Lundstrom
2026-06-05 19:04:33
(2 weeks ago)
https://www.eagleeye-intelligence.com โ WordPress attack. Automatically detected and blocked.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 16:09:17
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccou ...
show more
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccount.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 12:09:12.123255 2026] [security2:error] [pid 29654:tid 29654] [client 65.254.225.213:57770] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||writebetweenthelines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "writebetweenthelines.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiL0qKeCT3zIzmyXZg6LQAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 12:54:53
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccou ...
show more
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccount.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 08:54:47.684654 2026] [security2:error] [pid 17757:tid 17757] [client 65.254.225.213:36648] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "celebritybikinigossip.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiLHFwx0cZ5ODxApY7VehwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 10:27:06
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccou ...
show more
(mod_security) mod_security (id:225170) triggered by 65.254.225.213 (65-254-225-213.yourhostingaccount.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 06:27:03.209606 2026] [security2:error] [pid 12671:tid 12683] [client 65.254.225.213:33410] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosureinternetservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosureinternetservices.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiKkd2Vo5_VeD1y-vE8VJgAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack