๐ง๐ช
cmbplf
2026-10-06 21:02:02
(22 minutes ago)
5.357 requests to many distinct domains in 1 hour (3w6d4h)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 20:27:04
(57 minutes ago)
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:26:56.306570 2026] [security2:error] [pid 18256:tid 18274] [client 72.61.237.85:38618] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nabsci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nabsci.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asVZkEsmaZ_VUrkxiI4eagAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
Zhengka.net
2026-10-06 20:14:16
(1 hour ago)
zhengka.net security honeypot hit; jail=zhengka.net_honeypot; ip=72.61.237.85
Port Scan
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-06 20:12:06
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-06 20:08:53
(1 hour ago)
[06/Oct/2026:23:08:52 +0300] -- 72.61.237.85 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-js ...
show more
[06/Oct/2026:23:08:52 +0300] -- 72.61.237.85 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/wp/v2/users?_fields=slug&per_page=100&page=1 HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 19:52:42
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 15:52:35.408413 2026] [security2:error] [pid 20262:tid 20262] [client 72.61.237.85:45646] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eduempowermentsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eduempowermentsolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asVRg8SAIj5oe5cVl3-GtwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
Lacika555
2026-10-06 18:58:54
(2 hours ago)
RdpGuard detected brute-force attempt on SMTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 17:58:59
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 13:58:55.808306 2026] [security2:error] [pid 21091:tid 21091] [client 72.61.237.85:35736] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||become-a-medicalsalesrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "become-a-medicalsalesrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asU238uPVde04uD3R-a81QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 17:35:48
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 13:35:43.701302 2026] [security2:error] [pid 6558:tid 6558] [client 72.61.237.85:41640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.investlocalnm.socialenterprise.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.investlocalnm.socialenterprise.net"] [uri "/wp-json/wp/v2/users"] [unique_id "asUxb6rHsh1OETcO87cNswAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 17:04:01
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 13:03:57.769774 2026] [security2:error] [pid 8472:tid 8472] [client 72.61.237.85:38674] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||llew.life.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "llew.life.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asUp_YU9ZMxmAg-pV0d-TAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-06 15:52:38
(5 hours ago)
Web exploit attempt | method: GET | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; W ...
show more
Web exploit attempt | method: GET | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:46:28
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:46:21.614093 2026] [security2:error] [pid 20823:tid 20823] [client 72.61.237.85:46436] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aquanauticsige.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aquanauticsige.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asUXzTPN-Eq5s2jhO7EZkgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:06:48
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 72.61.237.85 (srv1179531.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:06:40.761766 2026] [security2:error] [pid 18332:tid 18332] [client 72.61.237.85:48336] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||faithlines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "faithlines.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asUOgDXY2-LlKN1nSLmJYwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-29 08:55:04
(1 week ago)
Detected mail brute force attack from different servers
Brute-Force