๐ฉ๐ช
LRob
2026-09-19 18:09:47
(16 minutes ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-19 18:09 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 16:55:55
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 12:55:48.228758 2026] [security2:error] [pid 9057:tid 9057] [client 85.90.190.8:47040] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||constructiondomex.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "constructiondomex.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6-lAxrTXoLosiXxwv_xgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 14:10:49
(4 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 14:00:32
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 10:00:27.689554 2026] [security2:error] [pid 11409:tid 11409] [client 85.90.190.8:51702] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doublenaughtspycar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doublenaughtspycar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6Ve5_nbQX-mbKPJ0Wp8AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 13:42:17
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 09:42:11.970022 2026] [security2:error] [pid 11761:tid 11761] [client 85.90.190.8:37428] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drdot.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drdot.xyz"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6RM2WiPkol71XpcFEg2wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-09-19 12:13:13
(6 hours ago)
WordPress user enumeration attempt detected.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 12:08:37
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:08:31.129391 2026] [security2:error] [pid 18215:tid 18215] [client 85.90.190.8:36924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||altoshp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "altoshp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq57P8zusbdNGacJp6ILnQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 12:08:10
(6 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐ฌ๐ง
oja
2026-09-19 12:03:10
(6 hours ago)
Aggressive web scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:08:23
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 85.90.190.8 (arrakis8.dlweb.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:08:13.883891 2026] [security2:error] [pid 27678:tid 27678] [client 85.90.190.8:46642] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stacyfarm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5tHWTgoYYhzX2BiufLUwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-19 10:53:25
(7 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 85.90.190.8 (HU/Hungary/arrakis8.dlweb.hu): 1 ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 85.90.190.8 (HU/Hungary/arrakis8.dlweb.hu): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 85.90.190.8 - - [19/Sep/2026:12:53:19 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12112 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0" "-" host=coget.srl
show less
Port Scan
๐ฆ๐บ
A.i.D.A.N.N
2026-09-19 10:39:28
(7 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-31 04:15:05
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
mnsf
2026-08-31 00:06:29
(2 weeks ago)
Login Too Frequent (13)
Brute-Force
Web App Attack
Anonymous
2026-08-30 17:15:55
(2 weeks ago)
Web attack blocked by Wordfence on vestingstadvalkenburg.nl (1 hit). Reported by CRMON.
Web App Attack