๐ฉ๐ช
todix
2026-09-20 12:59:59
(14 hours ago)
WebAttack or semilar from 74.208.48.105
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-20 05:01:01
(22 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-20 04:15:32
(23 hours ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐ฉ๐ช
maxpower
2026-09-20 03:22:58
(23 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 74.208.48.105 (US/United States/-): 1 in the l ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 74.208.48.105 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 74.208.48.105 - - [20/Sep/2026:05:22:57 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12164 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0" "-" host=johnfante.info
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-20 03:17:32
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 23:17:27.640433 2026] [security2:error] [pid 13477:tid 13477] [client 74.208.48.105:36248] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||495metro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "495metro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9QRy8CdlLBlqNIA7L_ZAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 01:26:36
(1 day ago)
74.208.48.105 - - [20/Sep/2026:01:24:23 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 ( ...
show more
74.208.48.105 - - [20/Sep/2026:01:24:23 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0" "-"
74.208.48.105 - - [20/Sep/2026:01:24:26 +0000] "GET /?author=3 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0" "-"
74.208.48.105 - - [20/Sep/2026:01:24:48 +0000] "GET /?author=5 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:98.0) Gecko/20100101 Firefox/98.0" "-"
74.208.48.105 - - [20/Sep/2026:01:24:47 +0000] "GET /?author=4 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0" "-"
74.208.48.105 - - [20/Sep/2026:01:25:41 +0000] "GET /?author=6 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 00:59:55
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 20:59:51.203172 2026] [security2:error] [pid 28345:tid 28345] [client 74.208.48.105:39482] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lgbtqhistoryinaustin.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lgbtqhistoryinaustin.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8wBzGIL8CWDsbgW765pAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 20:00:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 16:00:49.672178 2026] [security2:error] [pid 1870352:tid 1870352] [client 74.208.48.105:53792] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webuydinwiddiehouses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webuydinwiddiehouses.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7p8fTWDnUbv1pPZDqniQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 18:48:43
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:48:37.889974 2026] [security2:error] [pid 27656:tid 27656] [client 74.208.48.105:33200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lowkeytiki.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lowkeytiki.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7ZBRj3HAg2w-qkQRfSCwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 16:47:29
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 16:34:36
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 12:34:30.756797 2026] [security2:error] [pid 27736:tid 27736] [client 74.208.48.105:51566] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||trinitydent.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "trinitydent.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq65lu3SGYtNo7vwfL6INgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:27:22
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:27:18.358989 2026] [security2:error] [pid 30091:tid 30104] [client 74.208.48.105:54670] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||datuinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "datuinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5xljrMWSh0uC0FMnIS4AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:22:18
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.48.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:22:15.003460 2026] [security2:error] [pid 3624:tid 3624] [client 74.208.48.105:38660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pathpa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pathpa.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5iV0np2y7JWsF5Z7yI9AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-17 23:11:01
(3 days ago)
74.208.48.105 - - [17/Sep/2026:23:10:48 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 ( ...
show more
74.208.48.105 - - [17/Sep/2026:23:10:48 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0" "-" edge="74.208.48.105"
74.208.48.105 - - [17/Sep/2026:23:10:49 +0000] "GET /?author=3 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0" "-" edge="74.208.48.105"
74.208.48.105 - - [17/Sep/2026:23:10:50 +0000] "GET /?author=4 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:42.0) Gecko/20100101 Firefox/42.0" "-" edge="74.208.48.105"
74.208.48.105 - - [17/Sep/2026:23:10:52 +0000] "GET /?author=5 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" "-" edge="74.208.48.105"
74.208.48.105 - - [17/Sep/2026:23:10:53 +0000] "GET /?author=6 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0" "-" edge="74.208.48.105"
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 10:20:40
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-17 10:20 UTC
show less
Hacking
Web App Attack