๐ณ๐ฑ
wlt-blocker
2026-06-03 22:17:18
(2 weeks ago)
Unauthorized access to webpage admin
Web App Attack
๐ซ๐ท
viki53
2026-06-03 21:09:45
(2 weeks ago)
Website hacking attempt (path: /wp-includes/id3/license.txt/feed)
Hacking
Web App Attack
Anonymous
2026-06-03 19:14:25
(2 weeks ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-03 12:39:09
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 173.239.226.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 173.239.226.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 08:39:03.410994 2026] [security2:error] [pid 15693:tid 15693] [client 173.239.226.158:9576] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.copanmaya.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.copanmaya.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiAgZwf8MWQrlBn7dMHnmAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-03 11:30:03
(2 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 11:11:27
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 173.239.226.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 173.239.226.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 07:11:20.127978 2026] [security2:error] [pid 4016:tid 4016] [client 173.239.226.158:17839] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coolerboxes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coolerboxes.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiAL2IRLvSVo0LtSXg_YygAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-06-03 10:40:51
(2 weeks ago)
(wordpress-404) Searching for non-existent wordpress installs from 173.239.226.158 (US/United States ...
show more
(wordpress-404) Searching for non-existent wordpress installs from 173.239.226.158 (US/United States/Nevada/Las Vegas/-/[redacted])
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-03 10:38:02
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 173.239.226.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 173.239.226.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 06:37:54.096267 2026] [security2:error] [pid 11598:tid 11598] [client 173.239.226.158:8818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.convtek.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiAEAqRiRGGjczQQtNI2CwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
konseptit
2026-01-28 16:28:46
(4 months ago)
(smtpauth) Failed SMTP AUTH login from 173.239.226.158 (US/United States/-)
Brute-Force
๐ฉ๐ช
SMARTNET
2025-11-26 07:00:13
(6 months ago)
Aisuru(Mirai variant) DDoS
DDoS Attack
๐ฉ๐ช
mygnuos.tk
2025-11-05 02:28:45
(7 months ago)
Actively scanning for abnormal web paths
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-20 10:12:17
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 173.239.226.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 173.239.226.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 20 06:12:07.845520 2025] [security2:error] [pid 2168:tid 2168] [client 173.239.226.158:24128] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||koswerks.net|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "koswerks.net"] [uri "/index.bak"] [unique_id "aPYK97hVqu2NW9RMVrcmdAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2025-10-07 07:48:11
(8 months ago)
Web App Attack
Web App Attack
๐ง๐พ
StatsMe
2025-06-08 23:14:55
(1 year ago)
2025-06-08T02:32:04.867043+0300
ET SCAN NMAP -sS window 1024
Port Scan
๐ฌ๐ง
Joe-Mark
2025-06-08 14:40:43
(1 year ago)
Found Matty Roberts Blocklist / proto=6 . srcport=56033 . dstport=25565 . (822)
Port Scan