🇺🇸
lostswordfish.com
2026-09-09 05:04:04
(6 hours ago)
Wordfence waf block on wp20190711M4
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:21:17
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.235.93.171 (85-235-93-171.naracom.hu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.235.93.171 (85-235-93-171.naracom.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:21:11.206512 2026] [security2:error] [pid 30186:tid 30186] [client 85.235.93.171:60210] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dougrhodes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dougrhodes.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDet4y-SwFSgJEdbc3s2wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:36:30
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.235.93.171 (85-235-93-171.naracom.hu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.235.93.171 (85-235-93-171.naracom.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:36:25.291834 2026] [security2:error] [pid 23928:tid 23928] [client 85.235.93.171:39550] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cartiologyfilms.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cartiologyfilms.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDUObnTqlODXo7j19o4ugAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:00:51
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.235.93.171 (85-235-93-171.naracom.hu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.235.93.171 (85-235-93-171.naracom.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:00:44.289576 2026] [security2:error] [pid 7167:tid 7167] [client 85.235.93.171:54200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clcmillvale.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clcmillvale.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC9zAeIydHO9roG0LoyawAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 21:35:47
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:25:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 85.235.93.171 (85-235-93-171.naracom.hu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.235.93.171 (85-235-93-171.naracom.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:25:48.566990 2026] [security2:error] [pid 28174:tid 28174] [client 85.235.93.171:41552] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vr-squaredance.kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vr-squaredance.kdgsf.xyz"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_UnN4KYK6Wh_SYf8wX4AAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-26 22:26:36
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇨🇦
Blinker73
2026-08-05 23:43:26
(1 month ago)
2026-08-05T19:43 kernel: OUT= SRC=85.235.93.171 LEN=60 TOS=0x00 PREC=0x00 TTL=42 ID=40667 DF P ...
show more
2026-08-05T19:43 kernel: OUT= SRC=85.235.93.171 LEN=60 TOS=0x00 PREC=0x00 TTL=42 ID=40667 DF PROTO=TCP SPT=45854 DPT=23 WINDOW=65535 RES=0x00 SYN URGP=0
2026-08-05T19:43 kernel: OUT= SRC=85.235.93.171 LEN=60 TOS=0x00 PREC=0x00 TTL=42 ID=19388 DF PROTO=TCP SPT=53844 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
2026-08-05T19:43 kernel: OUT= SRC=85.235.93.171 LEN=60 TOS=0x00 PREC=0x00 TTL=42 ID=19390 DF PROTO=TCP SPT=53844 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=
show less
Port Scan
Anonymous
2026-08-05 22:51:18
(1 month ago)
2026-08-06T00:51:18.071424+02:00 vps kernel: [2341121.053749] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=f ...
show more
2026-08-06T00:51:18.071424+02:00 vps kernel: [2341121.053749] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=85.235.93.171 DST=54.37.14.118 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=17370 DF PROTO=TCP SPT=58040 DPT=23 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
Brute-Force
🇺🇸
MPL
2026-08-05 14:24:26
(1 month ago)
tcp ports: 22,23 (4 or more attempts)
Port Scan
🇺🇸
kosada.com
2026-08-03 14:14:52
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-01-15 21:01:12
(7 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-post.asp
show less
Bad Web Bot
Exploited Host
Anonymous
2025-11-24 18:50:00
(9 months ago)
scanning http requests from known botnet
Web App Attack