🇲🇹
Malta
2026-08-26 06:43:59
(4 days ago)
85.128.143.123 - - [26/Aug/2026:08:43:59 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
85.128.143.123 - - [26/Aug/2026:08:43:59 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/140.0.0.0"
show less
Hacking
Web App Attack
🇫🇷
SpaceHost-Server
2026-05-12 22:34:41
(3 months ago)
Brute-Force
Web App Attack
🇫🇷
SpaceHost-Server
2026-05-11 22:33:15
(3 months ago)
Brute-Force
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-05-11 05:29:06
(3 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇩🇪
stinpriza
2026-05-11 04:40:53
(3 months ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 23:46:39
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 19:46:32.583948 2026] [security2:error] [pid 4019:tid 4019] [client 85.128.143.123:42306] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marianozaro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marianozaro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agEY2EjDe25iwbjkP9Y1ngAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 09:15:51
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 05:15:44.577382 2026] [security2:error] [pid 31187:tid 31267] [client 85.128.143.123:33278] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||motoadvrally.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "motoadvrally.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agBMwLjVJT61SxuJeqK5XAAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 08:48:52
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 04:48:48.117021 2026] [security2:error] [pid 32631:tid 32631] [client 85.128.143.123:48092] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.magacine.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.magacine.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "agBGcHpiEvr549SpfYYMQwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 07:41:06
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 03:40:58.540478 2026] [security2:error] [pid 31023:tid 31023] [client 85.128.143.123:49656] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ohanameetup.party|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ohanameetup.party"] [uri "/wp-json/wp/v2/users"] [unique_id "agA2ioN9x2r-ByhpVrGFmQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 05:33:28
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 01:33:24.602517 2026] [security2:error] [pid 3953:tid 3953] [client 85.128.143.123:34666] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.prcomputersolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.prcomputersolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agAYpNgo0_C5DK3_1-eZ5wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 03:51:16
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 23:51:09.090726 2026] [security2:error] [pid 31117:tid 31117] [client 85.128.143.123:52444] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.thorndikestudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agAArRDT9mq0V_C5RIQ8FQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 03:14:08
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 23:14:01.265005 2026] [security2:error] [pid 13932:tid 13932] [client 85.128.143.123:56596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kawkacevents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kawkacevents.com"] [uri "/wp-json/wp/v2/users"] [unique_id "af_3-WedFD_3PysdoxtrJQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-09 23:59:40
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.128.143.123 (static-akl123.rev.netart.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 19:59:32.698685 2026] [security2:error] [pid 5441:tid 5441] [client 85.128.143.123:56590] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.localpetsitters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.localpetsitters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "af_KZIarfEyvZrGz2FFw1AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
octageeks.com
2026-05-06 04:09:25
(3 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
🇲🇹
Malta
2026-05-05 14:26:13
(3 months ago)
85.128.143.123 - - [05/May/2026:16:26:13 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (MSIE 8.0; ...
show more
85.128.143.123 - - [05/May/2026:16:26:13 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (MSIE 8.0; Windows NT 6.0; Trident/7.0; rv:11.0) like Gecko"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force