๐บ๐ธ
TPI-Abuse
2026-09-22 13:51:10
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:51:02.736779 2026] [security2:error] [pid 9974:tid 9974] [client 79.127.171.226:64305] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||templeantiques.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "templeantiques.org"] [uri "/wp-json/wp/v2/users"] [unique_id "arKHxgsxolc6c0ZFIg1s0wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-09-22 13:18:26
(11 hours ago)
Detected crowdsecurity/http-cve-probing attack pattern. Reported by CrowdSec IDS.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 12:58:28
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:58:20.998462 2026] [security2:error] [pid 8225:tid 8225] [client 79.127.171.226:52824] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||teghekatu24.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "teghekatu24.am"] [uri "/wp-json/wp/v2/users"] [unique_id "arJ7bJWSF1Yy6G5Pc3ZdxgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
lolyay
2026-09-22 12:41:43
(11 hours ago)
79.127.171.226 - - [22/Sep/2026:12:41:41 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 404 166 "-" "Mozil ...
show more
79.127.171.226 - - [22/Sep/2026:12:41:41 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 404 166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
79.127.171.226 - - [22/Sep/2026:12:41:42 +0000] "GET /wp-json/wp/v2/users HTTP/1.1" 200 648 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
๐ต๐ฑ
Budyn
2026-09-22 12:35:06
(11 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: status.astropot.website | URI: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: {"requests":[{"method":"POST","path":"/wp/v2/posts","body":{"author__not_in":["1) UNION SELECT user_login,user_pass FROM wp_users--"]}}]}
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:27:24
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:27:18.395432 2026] [security2:error] [pid 29341:tid 29465] [client 79.127.171.226:51111] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogamur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogamur.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arJ0JsVjhQFRju_Z0itkjQAAAkU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 12:20:29
(12 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-22 11:44:47
(12 hours ago)
[22/Sep/2026:14:44:47 +0300] -- 79.127.171.226 Ban reason: Scanner [CMS_GENERIC] | Request: POST /wp ...
show more
[22/Sep/2026:14:44:47 +0300] -- 79.127.171.226 Ban reason: Scanner [CMS_GENERIC] | Request: POST /wp-json/batch/v1 HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:41:47
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:41:42.932823 2026] [security2:error] [pid 917:tid 917] [client 79.127.171.226:62334] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||roadrunnerenergypark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "roadrunnerenergypark.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arJpdpeMVGk1pp8kmeG9YwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-09-22 11:21:02
(13 hours ago)
CrowdSec: crowdsecurity/http-cve-probing
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 10:16:22
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:16:18.676792 2026] [security2:error] [pid 20145:tid 20145] [client 79.127.171.226:63196] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||taptaptennis.abecasis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "taptaptennis.abecasis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arJVcuOMeI6sheqmQkd2NQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:53:27
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:53:23.123948 2026] [security2:error] [pid 2114:tid 2114] [client 79.127.171.226:60650] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||themadwriter.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "themadwriter.us"] [uri "/wp-json/wp/v2/users"] [unique_id "arJCAwVJ8ujYHuhAw3kgyAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-22 08:39:56
(15 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 79.127.171.226 (unn-79-127-171-226.datapacket. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 79.127.171.226 (unn-79-127-171-226.datapacket.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 79.127.171.226 - - [22/Sep/2026:10:39:54 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 752 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "-" host=thekna.eu
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 08:25:10
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.171.226 (unn-79-127-171-226.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:25:02.513991 2026] [security2:error] [pid 19792:tid 19792] [client 79.127.171.226:65078] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rimworld.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rimworld.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arI7Xu0cAacXmQPyRmPxeQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฐ
EVISION
2026-09-21 06:39:46
(1 day ago)
Automatic report from MS firewall log.
https://github.com/Ragnarocek/Windows_FW_AbuseIPDB_Reporti ...
show more
Automatic report from MS firewall log.
https://github.com/Ragnarocek/Windows_FW_AbuseIPDB_Reporting
show less
Port Scan
Hacking
Brute-Force