๐ฉ๐ช
FeG Deutschland
2026-09-18 05:36:48
(19 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-16 14:58:54
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:50:09
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:50:02.657763 2026] [security2:error] [pid 10511:tid 10511] [client 83.97.117.215:52223] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realsugardaddy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realsugardaddy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqpKKk5V-PLE1J-GTP2cgwAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-14 19:11:15
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
kosada.com
2026-08-28 22:41:20
(3 weeks ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-25 02:09:14
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 22:09:08.025317 2026] [security2:error] [pid 11360:tid 11484] [client 83.97.117.215:56237] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pref-realestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pref-realestate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoz5RCE43_PNX5EeV8MmAwAAARg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-17 19:58:57
(1 month ago)
Web password guessing
Brute-Force
Anonymous
2026-08-13 15:00:07
(1 month ago)
Unauthorized access attempt to administration interfaces (wp-admin, phpMyAdmin, panel, etc). Automat ...
show more
Unauthorized access attempt to administration interfaces (wp-admin, phpMyAdmin, panel, etc). Automated scanning blocked by fail2ban.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-04 01:18:41
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 21:18:32.656984 2026] [security2:error] [pid 6176:tid 6176] [client 83.97.117.215:36183] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cns518.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cns518.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anE96P4Wn6Cm8Jih3g_5yQAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Yepngo
2026-07-14 05:47:07
(2 months ago)
83.97.117.215 - - [14/Jul/2026:07:45:48 +0200] "POST /wp-login.php HTTP/2.0" 200 11351 "https://yepn ...
show more
83.97.117.215 - - [14/Jul/2026:07:45:48 +0200] "POST /wp-login.php HTTP/2.0" 200 11351 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
83.97.117.215 - - [14/Jul/2026:07:47:06 +0200] "POST /wp-login.php HTTP/2.0" 200 11351 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-09 08:42:32
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 04:42:29.474554 2026] [security2:error] [pid 6335:tid 6335] [client 83.97.117.215:34257] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sieder.com.ar|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sieder.com.ar"] [uri "/wp-json/wp/v2/users"] [unique_id "ak9e9cw_GLrT8NXApHsDpQAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-29 12:28:34
(2 months ago)
Fail2Ban banned 83.97.117.215 for security violations in jail wp-armour. Log: 2026/06/29 12:28:33 [e ...
show more
Fail2Ban banned 83.97.117.215 for security violations in jail wp-armour. Log: 2026/06/29 12:28:33 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 83.97.117.215 | Target: wplogin" , client: 83.97.117.215, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ณ๐ฟ
Tripwire
2026-05-18 13:03:59
(4 months ago)
Probing for Wordpress - /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 03:40:16
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 83.97.117.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 23:40:10.675335 2026] [security2:error] [pid 3486498:tid 3486498] [client 83.97.117.215:58025] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stormwlf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stormwlf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adcfmqOYZl9CqytP4lxMHQAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-03-19 03:07:02
(5 months ago)
Unauthorized admin access - /admin/index.php
Brute-Force
Web App Attack