๐ณ๐ฑ
MyGlobalFlowers
2026-08-31 11:55:28
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 11:10:22
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io ...
show more
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:10:16.126550 2026] [security2:error] [pid 24708:tid 24708] [client 96.126.126.115:53974] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bervick.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bervick.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apVhGFcbLMeTVvuR2ZCzOAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-31 10:20:15
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: \sGET /[a-z0-9._-]{1,40}\.php\s (Match: GET /wp-login.php )
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 09:21:34
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io ...
show more
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:21:29.493123 2026] [security2:error] [pid 25918:tid 25918] [client 96.126.126.115:52640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nwtree.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nwtree.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "apVHmR16QQS8kdTsM88V_wAAAAY"], referer: http://www.nwtree.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 08:58:54
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io ...
show more
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:58:50.658687 2026] [security2:error] [pid 12212:tid 12212] [client 96.126.126.115:49124] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pathpa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pathpa.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apVCSu-dPSKAog34dzlqFgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-08-31 08:05:20
(2 days ago)
(wordpress) Failed wordpress login from 96.126.126.115 (US/United States/ip-96-126-126-115.cloudezap ...
show more
(wordpress) Failed wordpress login from 96.126.126.115 (US/United States/ip-96-126-126-115.cloudezapp.io)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-31 07:13:46
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io ...
show more
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:13:40.843791 2026] [security2:error] [pid 6520:tid 6520] [client 96.126.126.115:60084] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zost.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zost.net"] [uri "/wp-json/wp/v2/users"] [unique_id "apUppLOWfwKAljbzoMCF_gAAABs"], referer: http://zost.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-08-31 06:43:14
(2 days ago)
scans/SQL injection/spam posts : 2 queries
Web App Attack
SQL Injection
๐ฎ๐ฉ
Burayot
2026-08-31 05:45:16
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 96.126.126.115 (US/United States/ip ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 96.126.126.115 (US/United States/ip-96-126-126-115.cloudezapp.io): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
sfmet-admin
2026-08-31 05:19:15
(2 days ago)
96.126.126.115 - - [31/Aug/2026:05:19:14 +0000] "GET /wp-login.php HTTP/2.0" 200 33 "http://sfmet.co ...
show more
96.126.126.115 - - [31/Aug/2026:05:19:14 +0000] "GET /wp-login.php HTTP/2.0" 200 33 "http://sfmet.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
...
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-08-31 05:16:16
(2 days ago)
Web vulnerability probing: /wp-login.php
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-31 05:13:00
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 03:26:28
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io ...
show more
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:26:20.884772 2026] [security2:error] [pid 7049:tid 7049] [client 96.126.126.115:43070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theamarals.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apT0XIlE01N544HURjXdGQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 03:05:56
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io ...
show more
(mod_security) mod_security (id:225170) triggered by 96.126.126.115 (ip-96-126-126-115.cloudezapp.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:05:50.219653 2026] [security2:error] [pid 16384:tid 16384] [client 96.126.126.115:54858] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ixd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ixd.net"] [uri "/wp-json/wp/v2/users"] [unique_id "apTvjosuK7-trcqy4BMx6wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
etu brutus
2026-08-31 02:23:44
(2 days ago)
96.126.126.115 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack