🇺🇸
TPI-Abuse
2026-09-08 11:20:35
(18 minutes ago)
(mod_security) mod_security (id:225170) triggered by 89.221.126.160 (balticom-126-160.balticom.lv): ...
show more
(mod_security) mod_security (id:225170) triggered by 89.221.126.160 (balticom-126-160.balticom.lv): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:20:27.776793 2026] [security2:error] [pid 15627:tid 15627] [client 89.221.126.160:38966] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.edmontonareahomes.digitalracemedia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.edmontonareahomes.digitalracemedia.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_ve8_8jBOINWJL8GlmOwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:14:36
(24 minutes ago)
Web application attack detected.
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 11:04:22
(34 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:22:47
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 89.221.126.160 (balticom-126-160.balticom.lv): ...
show more
(mod_security) mod_security (id:225170) triggered by 89.221.126.160 (balticom-126-160.balticom.lv): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:22:43.142939 2026] [security2:error] [pid 20262:tid 20262] [client 89.221.126.160:46368] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodfrequencies.circleofsound.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodfrequencies.circleofsound.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_h8wcD0zPNT7i_Mfjy1wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:55:17
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 89.221.126.160 (balticom-126-160.balticom.lv): ...
show more
(mod_security) mod_security (id:225170) triggered by 89.221.126.160 (balticom-126-160.balticom.lv): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:55:09.048954 2026] [security2:error] [pid 1711:tid 1711] [client 89.221.126.160:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.southernbroadcast.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_bfROxX_SXGqgswCymqAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-08 04:14:47
(7 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
LRob
2026-09-07 10:06:50
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-09-07 10:06 UTC
show less
Hacking
Web App Attack
🇸🇬
garrymenata
2026-08-23 20:20:08
(2 weeks ago)
89.221.126.160 - - [24/Aug/2026:01:14:04 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; ...
show more
89.221.126.160 - - [24/Aug/2026:01:14:04 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
89.221.126.160 - - [24/Aug/2026:01:14:06 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
89.221.126.160 - - [24/Aug/2026:01:14:08 +0700] "GET / HTTP/1.1" 403 3258 "-" "Dalvik/2.1.0 (Linux; U; Android 12; Dcolor GD2 Build/SGZ4.240805.001)"
...
show less
DDoS Attack
Bad Web Bot
Anonymous
2026-01-16 15:29:54
(7 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
🇫🇮
albionfreemarket.com
2025-12-21 20:59:25
(8 months ago)
2025/12/21 20:59:25 [error] 296#296: *330144 limiting requests, excess: 50.350 by zone "limit_site", ...
show more
2025/12/21 20:59:25 [error] 296#296: *330144 limiting requests, excess: 50.350 by zone "limit_site", client: 89.221.126.160, server: albionfreemarket.com, request: "GET /chunk-J7UYIQDU.js HTTP/2.0", host: "albionfreemarket.com", referrer: "https://albionfreemarket.com/chunk-4ZDC27TH.js"
2025/12/21 20:59:25 [error] 296#296: *330144 limiting requests, excess: 50.350 by zone "limit_site", client: 89.221.126.160, server: albionfreemarket.com, request: "GET /chunk-J7UYIQDU.js HTTP/2.0", host: "albionfreemarket.com", referrer: "https://albionfreemarket.com/chunk-4ZDC27TH.js"
2025/12/21 20:59:25 [error] 299#299: *330143 limiting requests, excess: 50.350 by zone "limit_site", client: 89.221.126.160, server: albionfreemarket.com, request: "GET /chunk-B2NAKIRO.js HTTP/2.0", host: "albionfreemarket.com", referrer: "https://albionfreemarket.com/chunk-4ZDC27TH.js"
2025/12/21 20:59:25 [error] 299#299: *330143 limiting requests, excess: 50.350 by zone "limit_site", client: 89.221.126.160, server: alb
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2025-12-10 14:52:11
(8 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
🇳🇱
exxos
2025-11-02 20:53:55
(10 months ago)
Attacks with Bad user agents
Hacking
🇳🇱
exxos
2025-11-02 20:39:39
(10 months ago)
Attacks with Bad user agents
Hacking