๐ฉ๐ช
FeG Deutschland
2026-09-20 04:57:08
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1257
Exploited Host
Web App Attack
๐ฉ๐ช
PhishDestroy
2026-06-26 15:07:52
(2 months ago)
Automated scanning of phishdestroy.io for sensitive files (.env, config, credentials). Blocked by Cl ...
show more
Automated scanning of phishdestroy.io for sensitive files (.env, config, credentials). Blocked by Cloudflare WAF rule a85b24fd4b2b4574b9ac23a37dbd7d01. 1 blocked requests. Paths: /.env.local. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Sa
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 20:54:49
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 16:54:46.245815 2025] [security2:error] [pid 18548:tid 18548] [client 82.21.70.149:47358] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hshr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hshr.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPqWFp-V3eghmT-12vw-kgAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-23 20:35:43
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ง๐ช
voormedia
2025-10-23 18:30:22
(10 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 18:15:42
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 14:15:38.512700 2025] [security2:error] [pid 22925:tid 22925] [client 82.21.70.149:29188] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sierra-broadcasting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sierra-broadcasting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPpwyvzjBsGw41Se1hkmpQAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
S.O.B.A. Dev.
2025-10-23 17:46:37
(10 months ago)
Threat Blocked by BeeHive from (ASN:212238) (Network:CDNEXT) (Host:soba.dev) (Method:GET) (Protocol: ...
show more
Threat Blocked by BeeHive from (ASN:212238) (Network:CDNEXT) (Host:soba.dev) (Method:GET) (Protocol:HTTP/1.1) (Timestamp:2025-10-23T17:46:37Z)
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 17:19:39
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 13:19:33.632826 2025] [security2:error] [pid 25902:tid 25902] [client 82.21.70.149:49956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||astariafilms.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "astariafilms.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPpjpTsD1--oLaDrDoS09gAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 16:58:30
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 12:58:26.142504 2025] [security2:error] [pid 23426:tid 23426] [client 82.21.70.149:40628] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bizzmail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bizzmail.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aPpesgtj9Fljwk3hYDco-gAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-10-23 15:40:31
(10 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-23 15:10:25
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 11:10:21.809097 2025] [security2:error] [pid 18072:tid 18186] [client 82.21.70.149:4876] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eliteproductions.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eliteproductions.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "aPpFXUeGzBzP6K1OX7Q29AAAAcs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-23 13:41:54
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 82.21.70.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 09:41:48.219263 2025] [security2:error] [pid 22046:tid 22046] [client 82.21.70.149:63346] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jessicabaer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jessicabaer.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aPownB88qtIYCVcLoaf4UwAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-04 15:26:27
(1 year ago)
Botnet - login attempts with leaked random user/pass lists
Hacking
Brute-Force
Web App Attack