๐ฉ๐ช
NewWavesApp
2026-06-04 19:33:03
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 8.229.158.212 (US/United States/212.158 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 8.229.158.212 (US/United States/212.158.229.8.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐จ๐ญ
leo1305
2026-06-02 21:47:20
(1 week ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
Anonymous
2026-06-02 08:43:04
(1 week ago)
8.229.158.212 - - [02/Jun/2026:10:43:02 +0200] "GET /.env HTTP/1.1" 404 11827 "-" "Mozilla/5.0 (Wind ...
show more
8.229.158.212 - - [02/Jun/2026:10:43:02 +0200] "GET /.env HTTP/1.1" 404 11827 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-01 19:44:43
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ฏ๐ต
Valhalla
2026-06-01 00:27:57
(1 week ago)
/.env
Hacking
Web App Attack
๐ธ๐ช
KIDOS
2026-04-23 00:42:19
(1 month ago)
IIS malicious activity: high_400_error_rate (60% of requests are 400 errors)
Web App Attack
๐ง๐ช
cmbplf
2026-03-23 14:37:52
(2 months ago)
1.319 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-23 14:03:59
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 8.229.158.212 (212.158.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 8.229.158.212 (212.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 10:03:25.371116 2026] [security2:error] [pid 27129:tid 27232] [client 8.229.158.212:64954] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chelseyrae.antidote-it.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chelseyrae.antidote-it.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "acFILRCDlg11M2mT16GHYwAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-23 14:03:52
(2 months ago)
8.229.158.212 - - [23/Mar/2026:16:03:51 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.0" 404 469 " ...
show more
8.229.158.212 - - [23/Mar/2026:16:03:51 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.0" 404 469 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
8.229.158.212 - - [23/Mar/2026:16:03:51 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
8.229.158.212 - - [23/Mar/2026:16:03:52 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.0" 404 469 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
8.229.158.212 - - [23/Mar/2026:16:03:52 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
8.229.158.212 - - [23/Mar/2026:16:03:52 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.0" 404 469 "-"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
mondor.ro
2026-03-23 13:48:00
(2 months ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 8.229.158.212, Reason: ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 8.229.158.212, Reason:[(manifest) WordPress wlwmanifest.xml Attack 8.229.158.212 (US/United States/212.158.229.8.bc.googleusercontent.com): 10 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-03-23 13:46:40
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 8.229.158.212 (212.158.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 8.229.158.212 (212.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 09:46:31.714598 2026] [security2:error] [pid 17550:tid 17550] [client 8.229.158.212:49915] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||birdlovesfish.com.lakesidedetectiveagency.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "birdlovesfish.com.lakesidedetectiveagency.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "acFEN_aU-K4Y7s2meA-DFgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack