๐บ๐ธ
cwytech
2026-06-26 18:44:42
(2 months ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-25 13:10:06
(2 months ago)
Wordfence waf block on 1105merrystreet
Web App Attack
๐บ๐ธ
factor1
2026-06-25 10:51:38
(2 months ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
๐ท๐ด
INTEQ
2026-06-25 09:25:07
(2 months ago)
Web attack from 69.62.89.135
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 10:16:04
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 06:16:01.561400 2026] [security2:error] [pid 31583:tid 31583] [client 69.62.89.135:50916] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tracytappan.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajpc4fiGc0_bVsZPTMKdqAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 08:38:54
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 04:38:48.921643 2026] [security2:error] [pid 4482:tid 4482] [client 69.62.89.135:40634] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.brushmileage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.brushmileage.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajpGGCOSHgx20f2yn8eAtwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 20:39:34
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 16:39:27.018404 2026] [security2:error] [pid 30027:tid 30027] [client 69.62.89.135:48632] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.odinathletes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.odinathletes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajmdfraXKywJNnAx0TuBtAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-22 13:24:29
(2 months ago)
(wordpress) Failed wordpress login from 69.62.89.135 (BR/Brazil/srv941529.hstgr.cloud): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-22 12:44:52
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 08:44:48.350361 2026] [security2:error] [pid 6739:tid 6739] [client 69.62.89.135:36352] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vzan.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vzan.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkuQFLDxwy-iA1w13Z9FgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-21 23:32:54
(2 months ago)
[server.tmg.gr] httpd-suspicious-path: sites=crisis-management2021.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=crisis-management2021.eu; logs=/var/log/httpd/domains/crisis-management2021.eu.log; samples=/wp-json/wp/v2/users | /?author=1 | /?author=2
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 14:49:44
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 10:49:36.682555 2026] [security2:error] [pid 8956:tid 8956] [client 69.62.89.135:45210] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.realclean.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajf6AImCQmkBrqlvQlT9rQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 14:53:41
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 10:53:37.261908 2026] [security2:error] [pid 480:tid 480] [client 69.62.89.135:52572] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cloudex.link|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cloudex.link"] [uri "/wp-json/wp/v2/users"] [unique_id "ajapcQ5X-BwPgji3WTxmbAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-15 05:51:56
(2 months ago)
(wp_login_try) srv101 WP Login Attempt 69.62.89.135 (BR/Brazil/srv941529.hstgr.cloud): 10 in the las ...
show more
(wp_login_try) srv101 WP Login Attempt 69.62.89.135 (BR/Brazil/srv941529.hstgr.cloud): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 10:08:00
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:07:52.707783 2026] [security2:error] [pid 9957:tid 9962] [client 69.62.89.135:53692] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tkfay.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai59eFUCZEz1fRWmWfy_9gAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 06:52:44
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 69.62.89.135 (srv941529.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:52:39.297027 2026] [security2:error] [pid 19771:tid 19771] [client 69.62.89.135:56138] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.iee-usa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.iee-usa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai5Ptys0J-bf2UjxLVmRiQAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack