🇺🇸
LSPCCU
2026-09-09 11:11:58
(1 day ago)
TSEC Honeypot Network report. Threat score: 71/100. Categories: Port Scan, Hacking, Brute-Force, Web ...
show more
TSEC Honeypot Network report. Threat score: 71/100. Categories: Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: tanner. Context: 89.248.97.173 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
🇩🇪
bescared
2026-09-08 22:28:45
(1 day ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-09-06 13:52:03
(3 days ago)
Wordfence waf block on parsol
Web App Attack
Anonymous
2026-09-06 12:06:04
(4 days ago)
Trying to access config files
Web App Attack
🇺🇸
azminawwar
2026-09-05 11:54:38
(5 days ago)
[89.248.97.173] triggered by honeypot on port [80], Timestamp [2026-09-05T11:54:38Z]METHOD=GET PATH= ...
show more
[89.248.97.173] triggered by honeypot on port [80], Timestamp [2026-09-05T11:54:38Z]METHOD=GET PATH=/ HTTP=HTTP/1.1 UA="Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0"
show less
Port Scan
Hacking
Anonymous
2026-09-05 08:50:37
(5 days ago)
apache vulnerability scan
Web App Attack
🇩🇪
LRob
2026-09-05 02:54:02
(5 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /xmlrpc.php | 2026-09-05 02:54 UTC
show less
Hacking
Web App Attack
🇫🇷
SpaceHost-Server
2026-06-23 22:34:11
(2 months ago)
Brute-Force
Web App Attack
Anonymous
2026-06-21 13:08:41
(2 months ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-06-20 04:53:31
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominio ...
show more
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 00:53:27.527461 2026] [security2:error] [pid 10400:tid 10423] [client 89.248.97.173:39668] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pwihatah.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pwihatah.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajYcxwthSur7Io7A2rLMCQAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-19 18:50:25
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominio ...
show more
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 14:50:19.796799 2026] [security2:error] [pid 19116:tid 19116] [client 89.248.97.173:47640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doctoredwinalvarez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doctoredwinalvarez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWPa2Fg1m5FP33gBc4x0wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-18 23:12:30
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominio ...
show more
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 19:12:24.619177 2026] [security2:error] [pid 30682:tid 30682] [client 89.248.97.173:50220] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bickleton.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajR7WKXc1H5QZEYdJcKL7QAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-18 14:23:06
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominio ...
show more
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 10:22:57.359098 2026] [security2:error] [pid 22821:tid 22821] [client 89.248.97.173:34510] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.psychiatryabuse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.psychiatryabuse.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajP_QRnu1TQvTdqOKRnFbAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-18 01:11:30
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominio ...
show more
(mod_security) mod_security (id:225170) triggered by 89.248.97.173 (bornovastudio.vhost.interdominios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 21:11:24.893389 2026] [security2:error] [pid 23568:tid 23568] [client 89.248.97.173:38184] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.citizensforsanity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.citizensforsanity.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajNFvO96Nh2uBEdpR09JDwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-06-18 00:15:19
(2 months ago)
Domain : gherkindomains.co.uk
Rule : xmlrpc
2026-06-18 00:14:01 217.194.210.153 POST /xmlrpc.php - 8 ...
show more
Domain : gherkindomains.co.uk
Rule : xmlrpc
2026-06-18 00:14:01 217.194.210.153 POST /xmlrpc.php - 80 - 89.248.97.173 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0 - www.gherkindomains.co.uk 404 5 0 1455 400 3718 - -
show less
Web App Attack