🇮🇩
BoosterGold2099
2026-09-03 08:02:28
(21 hours ago)
Hacking
Exploited Host
Web App Attack
🇩🇪
FeG Deutschland
2026-09-03 03:29:48
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 13:01:41
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:01:36.113752 2026] [security2:error] [pid 10725:tid 10725] [client 93.177.95.252:18575] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fundaciondamashcc.org.ec|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fundaciondamashcc.org.ec"] [uri "/wp-json/wp/v2/users"] [unique_id "apbMsIlW93hh1BjXjg6GbAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-01 04:33:59
(3 days ago)
Many_bad_calls
Web App Attack
🇧🇪
taivas.nl
2026-08-31 05:32:14
(3 days ago)
Bad_requests
Bad Web Bot
🇮🇩
sockominfo
2026-08-27 04:00:09
(1 week ago)
Active Response: IP 93.177.95.252 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Rep ...
show more
Active Response: IP 93.177.95.252 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇮🇩
bps-statistics
2026-08-15 19:41:12
(2 weeks ago)
WP Login Scan Activities: "2026-08-16T02:41:12.758+07:00" "/wp-login.php" "93.177.95.252" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-08-16T02:41:12.758+07:00" "/wp-login.php" "93.177.95.252" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-10 00:01:07
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 20:01:01.764324 2026] [security2:error] [pid 1686367:tid 1686367] [client 93.177.95.252:49793] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||heartshapedboy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "heartshapedboy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ankUvcyQwUdorgiMcXXRzgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-08 21:48:34
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 17:48:27.934714 2026] [security2:error] [pid 1076975:tid 1076975] [client 93.177.95.252:59877] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||scala-global.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "scala-global.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anekKyiZlOSiC1EtnuBeigAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 13:16:57
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 09:16:53.954513 2026] [security2:error] [pid 3737226:tid 3737226] [client 93.177.95.252:19499] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naominixon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anHmRYGsJPqYtzaSfYWvowAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 16:41:28
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 12:41:23.907256 2026] [security2:error] [pid 5074:tid 5081] [client 93.177.95.252:13077] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||andestravel.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "andestravel.net"] [uri "/wp-json/wp/v2/users"] [unique_id "anDEs5IwWZh4XjZcSucz1wAAAIU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-08-01 06:12:00
(1 month ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-30 17:51:05
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.95.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 13:50:59.727948 2026] [security2:error] [pid 2511915:tid 2511915] [client 93.177.95.252:20965] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cosentient.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cosentient.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amuPA17M27u7ZywPfsfiZwAAAEQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
JimArchon72
2026-07-29 03:55:03
(1 month ago)
2026/07/29 03:51:32 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
🇫🇮
JimArchon72
2026-07-17 06:45:03
(1 month ago)
2026/07/17 06:42:15 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack