|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 20:49:24.325750 2026] [security2:error] [pid 8672:tid 8672] [client 100.24.110.95:43332] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.scswat.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.scswat.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aioGFFgsQ8_a79jEDBuZhQAAACk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 17:38:32.375606 2026] [security2:error] [pid 3940:tid 3940] [client 100.24.110.95:53738] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.whodatnation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.whodatnation.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ainZWCeEr-NRHUESnHWYTQAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 14:45:27.211064 2026] [security2:error] [pid 6736:tid 6736] [client 100.24.110.95:50270] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ideaofauniversity.website|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ideaofauniversity.website"] [uri "/wp-json/wp/v2/users"] [unique_id "aimwx5Iy6hekSVPslneyYQAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
[redacted] 100.24.110.95 - - [10/Jun/2026:06:38:58 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 100.24.110.95 - - [10/Jun/2026:06:38:58 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 100.24.110.95 - - [10/Jun/2026:06:38:58 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0"
[redacted] 100.24.110.95 - - [10/Jun/2026:06:39:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0"
[redacted] 100.24.110.95 - - [10/Jun/2026:06:39:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0"
[redacted] 100.24.110.95 - - [10/Jun/2026:06:39:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0"
[redacted] 100.24.110.95 - - [10/J
...
show less
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 21:41:12.650857 2026] [security2:error] [pid 25317:tid 25317] [client 100.24.110.95:52126] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||campnecon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "campnecon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aijAuG7nlZemP01oJ6doYwAAAB8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 13:13:44.413753 2026] [security2:error] [pid 3133:tid 3133] [client 100.24.110.95:40942] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||starcrestsales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "starcrestsales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aihJyEmMO0chWdwU7l2SuQAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:42:14.933755 2026] [security2:error] [pid 30170:tid 30170] [client 100.24.110.95:40690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.stoneybluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.stoneybluff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aientsk0A75v3ZfS3WdJMAAAABg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 21:45:24.602185 2026] [security2:error] [pid 22330:tid 22343] [client 100.24.110.95:52652] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daraluz.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daraluz.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aiYetJgQATpHGyIy-Er40wAAAIs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
dbmwebdesign
|
|
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 23:58:35.063216 2026] [security2:error] [pid 21635:tid 21651] [client 100.24.110.95:56160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thecraftsycat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thecraftsycat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiTsa707HDoVQz2s5_1a5wAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 21:28:42.713067 2026] [security2:error] [pid 17056:tid 17056] [client 100.24.110.95:33820] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ismaelcavazos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ismaelcavazos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiN3yqSWc8PtH5w-O8bsOAAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
[redacted] 100.24.110.95 - - [06/Jun/2026:02:55:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 100.24.110.95 - - [06/Jun/2026:02:55:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:44.0) Gecko/20100101 Firefox/44.0"
[redacted] 100.24.110.95 - - [06/Jun/2026:02:55:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0"
[redacted] 100.24.110.95 - - [06/Jun/2026:02:55:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0"
[redacted] 100.24.110.95 - - [06/Jun/2026:02:55:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0"
[redacted] 100.24.110.95 - - [06/Jun/2026:02:55:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0"
[redacted] 100.24.110.95 - - [06/J
...
show less
|
Hacking
Web App Attack
|
|
|
Anonymous
|
|
[server.tmg.gr] httpd-suspicious-path: sites=crisis-management2018.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=crisis-management2018.eu; logs=/var/log/httpd/domains/crisis-management2018.eu.log; samples=/wp-json/wp/v2/users | /?author=1 | /author/admin/
show less
|
Hacking
Web App Attack
|
|
|
Anonymous
|
|
[redacted] 100.24.110.95 - - [04/Jun/2026:21:50:04 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "M ...
show more
[redacted] 100.24.110.95 - - [04/Jun/2026:21:50:04 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0"
[redacted] 100.24.110.95 - - [04/Jun/2026:21:50:04 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0"
[redacted] 100.24.110.95 - - [04/Jun/2026:21:50:04 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0"
[redacted] 100.24.110.95 - - [04/Jun/2026:21:50:05 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"
[redacted] 100.24.110.95 - - [04/Jun/2026:21:50:05 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"
...
show less
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 100.24.110.95 (ec2-100-24-110-95.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 16:09:46.151304 2026] [security2:error] [pid 12172:tid 12172] [client 100.24.110.95:47822] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.feministvoice.blog|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.feministvoice.blog"] [uri "/wp-json/wp/v2/users"] [unique_id "aiCKChlmwFvkpp70qVAF1QAAABo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|