๐ฉ๐ช
FeG Deutschland
2026-08-06 08:28:19
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-05 13:15:56
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 81.12.27.222 (tehran-01.letscp.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 81.12.27.222 (tehran-01.letscp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 09:15:49.048014 2026] [security2:error] [pid 10272:tid 10272] [client 81.12.27.222:43332] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||support.leonardodecaprio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "support.leonardodecaprio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anM3hcM2kgCnF9S55u6A3wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
oalver
2026-08-01 14:25:38
(1 week ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-01. Risk score: 30/100.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 14:43:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 81.12.27.222 (tehran-01.letscp.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 81.12.27.222 (tehran-01.letscp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:43:19.414952 2026] [security2:error] [pid 3718233:tid 3718233] [client 81.12.27.222:60978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doctorbalog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doctorbalog.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amduhxV3JLMe9FYLg1mjDgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-19 02:25:15
(2 weeks ago)
WP Armour Plugin detection
Web Spam
Brute-Force
๐บ๐ธ
lostswordfish.com
2026-07-18 22:00:09
(3 weeks ago)
Wordfence waf block on registrymatters
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 16:23:04
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 81.12.27.222 (tehran-01.letscp.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 81.12.27.222 (tehran-01.letscp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 12:22:55.286544 2026] [security2:error] [pid 17421:tid 17421] [client 81.12.27.222:43588] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tomslawmd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tomslawmd.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akPtX-_likUMmBLEaCw-YwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 17:31:14
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 81.12.27.222 (tehran-01.letscp.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 81.12.27.222 (tehran-01.letscp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 13:31:05.978513 2026] [security2:error] [pid 13923:tid 13923] [client 81.12.27.222:33310] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dokuzadabirdeniz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dokuzadabirdeniz.com"] [uri "/wp-json/wp/v2/users/10"] [unique_id "akFaWTsj1_d7PJ3LNJ1sswAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-06-26 16:03:40
(1 month ago)
(wplogin_block) Blocked WP-Login Access Attempt 81.12.27.222 (IR/Iran/-/-/-/[AS51026 Dade Pardazi Mo ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 81.12.27.222 (IR/Iran/-/-/-/[AS51026 Dade Pardazi Mobinhost Co LTD]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 81.12.27.222 - - [26/Jun/2026:19:03:14 +0300] "GET /wp-login.php HTTP/2.0" 200 5188 "-" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
Anonymous
2025-12-26 18:00:30
(7 months ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2025-12-16 01:30:13
(7 months ago)
Failed Wordpress Logins
Web App Attack
๐น๐ท
rtbh.com.tr
2025-12-12 20:10:25
(7 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ต๐ฑ
IROK
2025-12-12 09:14:32
(7 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
๐ซ๐ท
ingroscart.it
2025-12-11 21:13:53
(7 months ago)
(wordpress) Failed wordpress login from 81.12.27.222 (IR/Iran/tehran-01.letscp.com)
Brute-Force
๐ฉ๐ช
Hazzard
2025-12-11 11:42:03
(7 months ago)
(wordpress) Failed wordpress login from 81.12.27.222 (IR/Iran/-/-/tehran-01.letscp.com/[redacted])
Brute-Force