๐จ๐ฆ
polycoda
2026-07-21 22:16:08
(1 hour ago)
๐ Probes for tons of inexistent files and/or PHP scripts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 22:14:56
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 18:14:49.244454 2026] [security2:error] [pid 3544731:tid 3544731] [client 74.208.9.170:33976] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||comicpreservation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "comicpreservation.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al_vWeFg2Ci4-MaU77LMIAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-21 22:08:26
(2 hours ago)
furst.com.au:443 74.208.9.170 - - [22/Jul/2026:08:08:24 +1000] "GET /?author=1 HTTP/1.1" 404 5145 "- ...
show more
furst.com.au:443 74.208.9.170 - - [22/Jul/2026:08:08:24 +1000] "GET /?author=1 HTTP/1.1" 404 5145 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ธ๐ฎ
administrator
2026-07-21 22:08:04
(2 hours ago)
2026-07-20 11:24:41,831 fail2ban.actions [1132]: NOTICE [apache-badbots] Ban 74.208.9.170
20 ...
show more
2026-07-20 11:24:41,831 fail2ban.actions [1132]: NOTICE [apache-badbots] Ban 74.208.9.170
2026-07-20 11:24:41,831 fail2ban.actions [1132]: NOTICE [apache-badbots] Ban 74.208.9.170
2026-07-20 11:24:41,831 fail2ban.actions [1132]: NOTICE [apache-badbots] Ban 74.208.9.170
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 21:54:32
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 17:54:27.299724 2026] [security2:error] [pid 1609531:tid 1609531] [client 74.208.9.170:51652] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tasteshop.l3l4.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tasteshop.l3l4.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al_qk6ifjIMNtC6Z4cOrbgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xxkodedxx
2026-07-21 21:54:00
(2 hours ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: US / AS8560 IONOS SE
Active: 21:53:14 UTC
Volume: 1 HTTP req
Probed: /?author=1
Status mix: 444ร1
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 21:08:28
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 17:08:20.928103 2026] [security2:error] [pid 28942:tid 28942] [client 74.208.9.170:51306] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||genevainvestors.internetnameregistration.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "genevainvestors.internetnameregistration.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "al_fxIeZXHZM0QJOlgjpxwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-07-21 20:47:56
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:47:46
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:47:41.121360 2026] [security2:error] [pid 22478:tid 22478] [client 74.208.9.170:59520] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michelehoop.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "al_a7UPlnoWbG5QHAcJ8NQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-21 20:44:45
(3 hours ago)
(wp_user_enum) srv101 WordPress User Enumeration 74.208.9.170 (US/United States/ip74-208-9-170.pbiaa ...
show more
(wp_user_enum) srv101 WordPress User Enumeration 74.208.9.170 (US/United States/ip74-208-9-170.pbiaas.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:28:29
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:28:24.325070 2026] [security2:error] [pid 3392:tid 3402] [client 74.208.9.170:45660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||testproperty.pref-realestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "testproperty.pref-realestate.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "al_WaMskSZbot15QI41h4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gigatech
2026-07-21 20:20:03
(3 hours ago)
Webserver Probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:03:43
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:03:38.133489 2026] [security2:error] [pid 1045:tid 1045] [client 74.208.9.170:52246] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artevoix.com.velvetculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artevoix.com.velvetculture.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al_Qmju4sFjZ7DEsp6fn5QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-07-21 19:04:30
(5 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:44:09
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.9.170 (ip74-208-9-170.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:44:01.772719 2026] [security2:error] [pid 6855:tid 6855] [client 74.208.9.170:36768] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vaghyst.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vaghyst.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "al-98eOHQQOFT5QbRXSaIAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack