Anonymous
2026-09-20 18:09:35
(5 hours ago)
[ssd5.kdns.gr] httpd-suspicious-path: sites=www.dentallaboratory.gr; logs=/var/log/httpd/domains/den ...
show more
[ssd5.kdns.gr] httpd-suspicious-path: sites=www.dentallaboratory.gr; logs=/var/log/httpd/domains/dentallaboratory.gr.log; samples=/wp-json/wp/v2/users | /wp-json/wp/v2/users?search=xtw | /?author=1
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-20 11:15:04
(12 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-09-20 07:07:23
(16 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 06:43:46
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 02:43:38.787056 2026] [security2:error] [pid 8560:tid 8637] [client 82.194.74.62:51568] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||minutosrobados.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "minutosrobados.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq-Amg_Xfmu_YH5uNgNWdwAAAdQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-20 01:31:46
(22 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐ฉ๐ช
maxpower
2026-09-20 00:36:10
(23 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 82.194.74.62 (ES/Spain/server.progresoweb.com) ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 82.194.74.62 (ES/Spain/server.progresoweb.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 82.194.74.62 - - [20/Sep/2026:02:36:08 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12114 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0" "-" host=johnfante.info
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 20:07:24
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 16:07:17.112907 2026] [security2:error] [pid 15792:tid 15792] [client 82.194.74.62:44586] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.allotrope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.allotrope.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7rdRd07btgmb7CUDz73AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 19:28:51
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:28:46.175995 2026] [security2:error] [pid 6227:tid 6227] [client 82.194.74.62:49288] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kmelson.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kmelson.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7ibq4QNrcRa_2lgANwUAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 18:41:58
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:41:55.480731 2026] [security2:error] [pid 30091:tid 30091] [client 82.194.74.62:44800] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bethanpearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bethanpearce.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7XczNkWQPUi5SKT2mMgwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 15:07:53
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 11:07:48.749616 2026] [security2:error] [pid 27303:tid 27303] [client 82.194.74.62:38318] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.asapstarsmogcheck.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.asapstarsmogcheck.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6lRNNYaPGv3xSL8mgQsQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-19 13:48:16
(1 day ago)
82.194.74.62 - - [19/Sep/2026:13:47:25 +0000] "GET /?author=1 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (W ...
show more
82.194.74.62 - - [19/Sep/2026:13:47:25 +0000] "GET /?author=1 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "-" edge="82.194.74.62"
82.194.74.62 - - [19/Sep/2026:13:47:30 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0" "-" edge="82.194.74.62"
82.194.74.62 - - [19/Sep/2026:13:47:36 +0000] "GET /?author=3 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" edge="82.194.74.62"
82.194.74.62 - - [19/Sep/2026:13:47:41 +0000] "GET /?author=4 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0" "-" edge="82.194.74.62"
82.194.74.62 - - [19/Sep/2026:13:47:47 +0000] "GET /?author=5 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0" "-" edge="82.194.74.62"
...
show less
Web App Attack
๐จ๐ญ
YF
2026-09-19 13:37:13
(1 day ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 16:19:24
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:19:16.710197 2026] [security2:error] [pid 6544:tid 6544] [client 82.194.74.62:53430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lyldevelopers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lyldevelopers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqwTBAOVqe_AuYLPYcoEtAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-17 16:18:24
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 15:36:53
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 82.194.74.62 (server.progresoweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 11:36:48.289630 2026] [security2:error] [pid 31077:tid 31079] [client 82.194.74.62:34592] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.darrylrichards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.darrylrichards.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqwJEO_qkQMkgJ7uORvjCgAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack