๐ฉ๐ช
niedson
2026-09-22 07:30:01
(2 days ago)
Automated honeypot trigger: scanner probing decoy admin/credential paths (e.g. /wp-admin, /phpmyadmi ...
show more
Automated honeypot trigger: scanner probing decoy admin/credential paths (e.g. /wp-admin, /phpmyadmin). Request dropped (HTTP 444) and source IP firewalled. Reported automatically.
show less
Port Scan
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 06:44:16
(2 days ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 79.127.171.198 (NL/The Netherlands/unn-79-127- ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 79.127.171.198 (NL/The Netherlands/unn-79-127-171-198.datapacket.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ณ๐ฑ
prinsbert
2026-09-22 06:06:12
(2 days ago)
Hit honeypot route /wp-json/batch/v1
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ง๐ช
cmbplf
2026-09-22 05:26:03
(2 days ago)
2.222 requests from abuseipdb.com blacklisted IP (4mos3w16h)
Brute-Force
Bad Web Bot
๐ฉ๐ช
big-cloud.nl
2026-09-22 03:57:24
(2 days ago)
Try to access /xmlrpc.php
Web App Attack
๐ท๐ด
iulianh
2026-09-22 03:02:19
(2 days ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-22 02:17:51
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:17:43.464862 2026] [security2:error] [pid 14732:tid 14732] [client 79.127.171.198:61071] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lahamradio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arHlR_LT3gRaPyz-0A2dQAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 01:55:17
(2 days ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 79.127.171.198 (NL/The Netherlands/unn-79-127- ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 79.127.171.198 (NL/The Netherlands/unn-79-127-171-198.datapacket.com): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ต๐ฑ
Budyn
2026-09-22 01:53:47
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: login.goblinpot.store | URI: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: {"requests":[{"method":"POST","path":"/wp/v2/posts","body":{"author__not_in":["1) UNION SELECT user_login,user_pass FROM wp_users--"]}}]}
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:58:10
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:58:07.182021 2026] [security2:error] [pid 31684:tid 31684] [client 79.127.171.198:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "local639.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arHSn5eU6g5ZWk-V40AR0wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:36:40
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:36:35.790303 2026] [security2:error] [pid 13606:tid 13606] [client 79.127.171.198:54741] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kwtlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kwtlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arHNk0bj6Mr_jq-KlrRwywAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
SystemAdmin
2026-09-22 00:22:43
(2 days ago)
Doing bad things...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:33:21
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:33:17.035324 2026] [security2:error] [pid 13336:tid 13336] [client 79.127.171.198:52611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rdhtrucking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rdhtrucking.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arG-vX_QppvdvpnvL9sTXgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:01:54
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.198 (unn-79-127-171-198.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:01:46.641528 2026] [security2:error] [pid 19824:tid 19852] [client 79.127.171.198:65372] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prismatik.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prismatik.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arG3WpANsXN-Rk1tQQjdfQAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack