๐ณ๐ฑ
Site.eu
2026-09-25 12:27:47
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐จ๐ณ
้น้น
2026-09-25 00:08:08
(3 days ago)
monitor: on VM-0-7-ubuntu | port: 10147 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporte ...
show more
monitor: on VM-0-7-ubuntu | port: 10147 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
maxpower
2026-09-21 19:37:48
(1 week ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 79.127.171.195 (unn-79-127-171-195.datapacket. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 79.127.171.195 (unn-79-127-171-195.datapacket.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 79.127.171.195 - - [21/Sep/2026:21:37:43 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "-" host=ramsesconsulting.com
show less
Port Scan
๐ต๐ฑ
Budyn
2026-09-21 19:27:53
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jira.budyn.xyz | URI: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: {"requests":[{"method":"POST","path":"/wp/v2/posts","body":{"author__not_in":["1) UNION SELECT user_login,user_pass FROM wp_users--"]}}]}
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-20 22:00:25
(1 week ago)
Auto-ban: 226 malicious requests on 2026-09-19 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 226 malicious requests on 2026-09-19 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 14:11:46
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:11:41.803059 2026] [security2:error] [pid 20210:tid 20210] [client 79.127.171.195:62798] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||manb.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "manb.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq_pnfuBV5L0bAXzD0W5PgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:36:48
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:36:44.041142 2026] [security2:error] [pid 17533:tid 17533] [client 79.127.171.195:59641] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||weismaninfrared.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "weismaninfrared.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq_hbD4bh9a3s2wRJy4a3AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 03:07:02
(1 week ago)
Automated web scanner. Requested suspicious paths: /wp-json/batch/v1. UTC: 2026-09-20 02:26:26.
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-20 02:47:00
(1 week ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 02:44:59
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 22:44:54.383330 2026] [security2:error] [pid 10894:tid 10894] [client 79.127.171.195:49502] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.btccasting.com.bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.btccasting.com.bamedica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9IpjfYoz4p3f_hNcZmzQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 02:11:28
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 22:11:22.443547 2026] [security2:error] [pid 11468:tid 11468] [client 79.127.171.195:50384] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tsiwny.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tsiwny.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9Ayn9TS5K3a16WtmTULwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 01:47:50
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:47:46.792039 2026] [security2:error] [pid 19101:tid 19101] [client 79.127.171.195:59974] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||whiterapperz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "whiterapperz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq87Qp2PSR5HpRY8eDYohAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 00:48:01
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.195 (unn-79-127-171-195.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 20:47:56.580683 2026] [security2:error] [pid 27822:tid 27822] [client 79.127.171.195:53195] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||onlineteacher.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "onlineteacher.info"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8tPE3PEYa-j178rNwa4wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-20 00:14:21
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-probing
Web App Attack
Hacking
๐บ๐ธ
Starburst SysOp Team
2026-09-19 23:36:34
(1 week ago)
(mod_security-custom) mod_security (id:225170) triggered by 79.127.171.195 (NL/The Netherlands/North ...
show more
(mod_security-custom) mod_security (id:225170) triggered by 79.127.171.195 (NL/The Netherlands/North Holland/Amsterdam/unn-79-127-171-195.datapacket.com/[AS60068 CDN77 _]): 1 in the last 3600 secs (0-srv1)
show less
Hacking