๐ฉ๐ช
maxpower
2026-09-19 18:43:54
(48 minutes ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 78.35.38.24 (DE/Germany/-): 1 in the last 3600 ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 78.35.38.24 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 78.35.38.24 - - [19/Sep/2026:20:43:50 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12075 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" host=orem.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 18:34:55
(57 minutes ago)
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:34:49.188851 2026] [security2:error] [pid 8020:tid 8020] [client 78.35.38.24:52988] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kerrywood.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kerrywood.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7VycdYUHls7FCnYHzByQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-19 18:32:08
(59 minutes ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: / (+1 more) | query: author=1 (+5 more) | 2026-09-19 18:32 UTC
show less
Hacking
Web App Attack
๐จ๐ญ
Origon
2026-09-19 14:55:15
(4 hours ago)
http-wordpress_user-enum - IP: 78.35.38.24 - time="2026-09-19T16:55:15+02:00" level=info msg="(555f ...
show more
http-wordpress_user-enum - IP: 78.35.38.24 - time="2026-09-19T16:55:15+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-wordpress_user-enum by ip 78.35.38.24 (DE/8422) : 4h ban on Ip 78.35.38.24" module=db
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-19 12:43:57
(6 hours ago)
cloudlinux2 fail2ban: 2026-09-19 14:38:58,316 fail2ban.actions [1813]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-19 14:38:58,316 fail2ban.actions [1813]: NOTICE [plesk-modsecurity] Unban 86.120.48.53cloudlinux2 fail2ban: 2026-09-19 14:41:58,950 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 86.120.48.53 - 2026-09-19 14:41:58cloudlinux2 fail2ban: 2026-09-19 14:42:09,142 fail2ban.filter [1813]: INFO [plesk-wordpress] Found 86.101.33.45 - 2026-09-19 14:42:09cloudlinux2 fail2ban: 2026-09-19 14:42:30,620 fail2ban.filter [1813]: INFO [plesk-wordpress] Found 85.247.229.96 - 2026-09-19 14:42:30cloudlinux2 fail2ban: 2026-09-19 14:42:32,823 fail2ban.filter [1813]: INFO [plesk-wordpress] Found 63.135.161.137 - 2026-09-19 14:42:32cloudlinux2 fail2ban: 2026-09-19 14:42:32,821 fail2ban.filter [1813]: INFO [plesk-wordpress] Found 63.135.161.147 - 2026-09-19 14:42:32cloudlinux2 fail2ban: 2026-09-19 14:42:40,236 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 78.35.38.24 - 2026-09-19 14:42:40cloudlinux2 fail2ban: 2026-0
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 12:25:31
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:25:27.087603 2026] [security2:error] [pid 24336:tid 24336] [client 78.35.38.24:52494] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thorndikestudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5_N3zBfcWXkQV2C0ZpKwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-19 11:30:17
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-09-19 11:14:32
(8 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 11:10:21
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:10:15.200339 2026] [security2:error] [pid 1331652:tid 1331652] [client 78.35.38.24:37608] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.mahjongcouture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.mahjongcouture.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5tlw3qcbeqp8tmdSF3mwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:47:57
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:47:53.146892 2026] [security2:error] [pid 26728:tid 26728] [client 78.35.38.24:47290] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.apexandroids.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.apexandroids.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5oWQu8-J9EnYhi3hGHJAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 10:31:59
(9 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-18 01:16:13
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 78.35.38.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:16:06.206395 2026] [security2:error] [pid 12799:tid 12799] [client 78.35.38.24:52002] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqyQ1j4KuVTXPgBgVnPiNgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack