๐ฉ๐ช
FeG Deutschland
2026-06-24 19:06:17
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 11:01:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 07:01:50.983507 2026] [security2:error] [pid 5030:tid 5030] [client 46.202.134.174:33980] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realclean.net"] [uri "/wp-json/wp/v2/users/3"] [unique_id "aju5HoWbQGuTLF2nlowVAAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 09:14:43
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 05:14:38.834168 2026] [security2:error] [pid 9834:tid 9834] [client 46.202.134.174:46466] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||midwayisland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "midwayisland.com"] [uri "/wp-json/wp/v2/users/3"] [unique_id "ajuf_qanVTRDJ0A2qxpBQwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 04:25:30
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 00:25:26.291338 2026] [security2:error] [pid 4936:tid 4936] [client 46.202.134.174:45242] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artizandecor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artizandecor.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ahfDtnTF84xlv80r5lgTyAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-28 03:26:11
(4 weeks ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 46.202.134.174 (FR/France/srv653676.hstgr.clo ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 46.202.134.174 (FR/France/srv653676.hstgr.cloud): 1 in the last 3600 secs (0-193)
show less
Hacking
๐ซ๐ท
mrcrassi
2026-05-27 23:36:47
(4 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: BLOCK
Protocol: HTTP/2 (POST method ...
show more
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
nationaleventpros.com
2026-05-27 21:46:44
(4 weeks ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-27 18:17:03
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 14:16:59.053717 2026] [security2:error] [pid 1896:tid 1896] [client 46.202.134.174:36446] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kmelson.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kmelson.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ahc1Gx2eguXPH8sBKo1KrwAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 15:57:07
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 11:57:02.006696 2026] [security2:error] [pid 16803:tid 16803] [client 46.202.134.174:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "southernbroadcast.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ahcUTv19MtOfyjLyq9gBQwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 14:21:13
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 10:21:09.187143 2026] [security2:error] [pid 10313:tid 10338] [client 46.202.134.174:57020] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.coloradomountain.homes|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.coloradomountain.homes"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ahb91YnObifvDZXeomdGkAAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-05-27 08:07:11
(4 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 05:11:25
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 46.202.134.174 (srv653676.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 01:11:18.893442 2026] [security2:error] [pid 16210:tid 16210] [client 46.202.134.174:40518] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inquisitivequincie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inquisitivequincie.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ahZ89hcpQ-0hV3NUt-hKTgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-05-27 02:45:32
(4 weeks ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ฒ๐น
Malta
2026-05-27 00:24:30
(4 weeks ago)
46.202.134.174 - - [27/May/2026:02:24:30 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Lin ...
show more
46.202.134.174 - - [27/May/2026:02:24:30 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐ฎ๐น
VHosting
2026-05-27 00:08:58
(4 weeks ago)
Detected mail brute force attack from 4 different servers
Brute-Force