๐ฉ๐ช
Hazzard
2026-06-20 06:27:55
(1 week ago)
(wordpress) Failed wordpress login from 91.134.230.130 (FR/France/-/-/host.dominioscaracas.com/[reda ...
show more
(wordpress) Failed wordpress login from 91.134.230.130 (FR/France/-/-/host.dominioscaracas.com/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-20 00:28:59
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:28:55.483800 2026] [security2:error] [pid 19851:tid 19851] [client 91.134.230.130:33092] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realclean.net"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ajXex3l1v5lZQpEWHqwPDQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 00:03:14
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:03:07.086619 2026] [security2:error] [pid 15892:tid 15974] [client 91.134.230.130:57894] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leadingedgesupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leadingedgesupply.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajXYu3w40AVnIraobSWsoQAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-19 23:27:57
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 23:17:03
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 19:16:59.715857 2026] [security2:error] [pid 8548:tid 8548] [client 91.134.230.130:52108] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nwuoregon.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nwuoregon.org"] [uri "/wp-json/wp/v2/users/5"] [unique_id "ajXN6yZ9q4oFWwv8l0kBGgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 22:22:13
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 18:22:08.283674 2026] [security2:error] [pid 20847:tid 20847] [client 91.134.230.130:33136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bzbdesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bzbdesigns.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajXBEMe8RAZp7s39q5Q2AAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
SpamStopper
2026-06-19 20:24:53
(1 week ago)
Automated mitigation by Fail2Ban firewall due to persistent security policy violations.
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 09:46:55
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 05:46:48.908500 2026] [security2:error] [pid 18773:tid 18773] [client 91.134.230.130:39920] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ruthbalser.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ruthbalser.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajUQCE_EskEfOcZSVsn5nwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-06-18 21:58:39
(1 week ago)
(wordpress) Failed wordpress login from 91.134.230.130 (FR/France/-/-/host.dominioscaracas.com/[reda ...
show more
(wordpress) Failed wordpress login from 91.134.230.130 (FR/France/-/-/host.dominioscaracas.com/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐ฒ๐น
Malta
2026-06-17 20:41:03
(1 week ago)
91.134.230.130 - - [17/Jun/2026:22:41:03 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
91.134.230.130 - - [17/Jun/2026:22:41:03 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
show less
Hacking
Web App Attack
VPN IP
๐ซ๐ท
solution.it
2026-06-17 19:01:44
(1 week ago)
[Wed Jun 17 21:01:43.881675 2026] [php7:error] [pid 561527:tid 561527] [client 91.134.230.130:60058] ...
show more
[Wed Jun 17 21:01:43.881675 2026] [php7:error] [pid 561527:tid 561527] [client 91.134.230.130:60058] script '/var/www/html/blog.solution.it/wp-login.php' not found or unable to stat
show less
Web App Attack
Anonymous
2026-06-17 06:20:52
(1 week ago)
2026-06-17T08:20:51.578649+02:00 zanati wp(www.serviceflow.co.za)[2543145]: Blocked authentication a ...
show more
2026-06-17T08:20:51.578649+02:00 zanati wp(www.serviceflow.co.za)[2543145]: Blocked authentication attempt for louis-stanford from 91.134.230.130
...
show less
Web App Attack
๐บ๐ธ
xxkodedxx
2026-06-16 21:12:15
(1 week ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 21:11:57โ21:11:58 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php
UA: "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 16:53:47
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 91.134.230.130 (host.dominioscaracas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 12:53:41.323744 2026] [security2:error] [pid 28939:tid 28984] [client 91.134.230.130:57312] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.store.emehache.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.store.emehache.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajF_lXFcU-t2tG_0Si5TgQAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-06-10 03:25:58
(2 weeks ago)
91.134.230.130 - - [10/Jun/2026:05:25:58 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
91.134.230.130 - - [10/Jun/2026:05:25:58 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force