๐ซ๐ท
dynamix
2026-09-26 23:13:05
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 18:31:02
(4 weeks ago)
Malicious web request: probing for secrets, traversal or a known exploit path | ua: wp2shell | 2026- ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | ua: wp2shell | 2026-09-01 18:31 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
C C
2026-08-09 08:39:49
(1 month ago)
Distributed scraping attack: 1469 req from 1403 rotating proxy IPs, waves of up to 150 req in 291s o ...
show more
Distributed scraping attack: 1469 req from 1403 rotating proxy IPs, waves of up to 150 req in 291s on a single URL | this IP: 1 req, 1 blocked
show less
Open Proxy
Bad Web Bot
Exploited Host
Web App Attack
๐ง๐ช
Saec
2026-07-15 16:42:03
(2 months ago)
Jarvis auto-ban: CF honeypot path /wp-login.php (2ร on saec.me)
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-06 05:45:42
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 01:45:35.387968 2026] [security2:error] [pid 5648:tid 5648] [client 88.218.47.199:48987] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vonkugelgen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vonkugelgen.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afrVf38Lyg1bE63gVecz-wAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 02:08:15
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 22:08:09.943680 2026] [security2:error] [pid 29568:tid 29568] [client 88.218.47.199:37815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dietzengineers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dietzengineers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae7FCVIoA5OV8q5ISJCbAAAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 20:01:26
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 16:01:18.722284 2026] [security2:error] [pid 5540:tid 5540] [client 88.218.47.199:61015] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||phuket-boatcharter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "phuket-boatcharter.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aep6jihodKmjZXyARXq9OgAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-04-17 14:57:01
(5 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-24 21:46:18
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 17:46:13.780934 2026] [security2:error] [pid 31914:tid 31914] [client 88.218.47.199:43251] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cyberclay.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cyberclay.net"] [uri "/wp-json/wp/v2/users"] [unique_id "acMGJWrKWqXFASLSIgx3hwAAABs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-24 09:29:19
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 05:29:11.115454 2026] [security2:error] [pid 17107:tid 17107] [client 88.218.47.199:37531] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||solidthought.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "solidthought.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acJZZ2Nsl4ci6aWdtiFHPwAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 22:05:21
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 18:05:13.435229 2026] [security2:error] [pid 23226:tid 23226] [client 88.218.47.199:34303] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drwolberg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drwolberg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acG5GfgFf-S5OGIexvnscgAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-03-09 18:45:45
(6 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Action: managed_challenge Source: firewallManaged ASN Description: AS-QUALITYNETWORK Country: FI Method: GET Timestamp: 2026-03-09T18:45:45Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
ambor
2026-03-06 02:32:48
(6 months ago)
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Web App Attack
๐บ๐ธ
xmission.com
2026-03-02 14:41:54
(6 months ago)
88.218.47.199 - - [02/Mar/2026:07:41:53 -0700] "POST /wp-login.php HTTP/1.1" 200 2326 "https://dooce ...
show more
88.218.47.199 - - [02/Mar/2026:07:41:53 -0700] "POST /wp-login.php HTTP/1.1" 200 2326 "https://dooce.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-01 15:32:51
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.47.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 10:32:48.209012 2026] [security2:error] [pid 8179:tid 8179] [client 88.218.47.199:37535] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bernsteinip.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aVaToJAs3BSz0J5ZGk4pvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack