๐ฉ๐ช
YF
2026-06-13 07:00:09
(1 hour ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 06:24:04
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 02:23:57.950075 2026] [security2:error] [pid 9385:tid 9385] [client 102.134.101.35:50924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dev.ericadamsdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dev.ericadamsdesign.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiz3fezUMbsRTFMuZKSqpwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
FireGuard Server
2026-06-13 05:55:12
(2 hours ago)
Blocked by OPNsense firewall; 8 hits, proto=tcp, ports=443
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-13 05:47:26
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 01:47:21.976603 2026] [security2:error] [pid 25751:tid 25751] [client 102.134.101.35:56822] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blublk.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blublk.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aizu6a8mZQPAWU6O-jcApwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 05:26:56
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 01:26:53.395994 2026] [security2:error] [pid 15474:tid 15474] [client 102.134.101.35:41020] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mkdesignndetailing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mkdesignndetailing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aizqHYuQ1qlbpkqgDgZ8lAAAABA"], referer: https://mkdesignndetailing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dklueh79
2026-06-13 05:16:15
(3 hours ago)
Probe for vulnerabilities. Path attempted: /wp-json/wp/v2/users
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 05:04:28
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 01:04:22.031963 2026] [security2:error] [pid 19936:tid 19936] [client 102.134.101.35:50986] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||isaiah.byles.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "isaiah.byles.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aizk1q27fZVHm5NQBGs3wAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 04:29:37
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 00:29:30.701665 2026] [security2:error] [pid 29740:tid 29740] [client 102.134.101.35:48584] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ibeautyexchange.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ibeautyexchange.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aizcqmo1nApH7-AZ75b8jQAAADY"], referer: https://ibeautyexchange.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ctidrv
2026-06-13 04:24:12
(3 hours ago)
Honeypot detection. Threat score: 70/100. Collector: honeypot. | Request: GET /wp-json/oembed/1.0/em ...
show more
Honeypot detection. Threat score: 70/100. Collector: honeypot. | Request: GET /wp-json/oembed/1.0/embed?url=https%3A%2F%2Fsaunacom.com&format=json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 | Attacks detected: rfi, open_redirect | Reasons: no_cookies, attack:rfi, attack:open_redirect
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 03:34:05
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 23:34:02.410270 2026] [security2:error] [pid 32232:tid 32232] [client 102.134.101.35:46206] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lusineweb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lusineweb.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aizPqhI4oyzbOWJAmokfQQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 02:56:43
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 22:56:36.286678 2026] [security2:error] [pid 20616:tid 20616] [client 102.134.101.35:34758] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ruthbalser.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ruthbalser.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aizG5BuvUOFPSM01x5zPGAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 02:34:18
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 22:34:14.507559 2026] [security2:error] [pid 22300:tid 22300] [client 102.134.101.35:55010] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nutz-r-us.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nutz-r-us.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aizBps9wH_FticxlXa6HggAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-13 02:28:43
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-06-13 01:05:38
(7 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 23:58:35
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 102.134.101.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 19:58:32.103784 2026] [security2:error] [pid 24502:tid 24502] [client 102.134.101.35:44642] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tarekshohaieb.online|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tarekshohaieb.online"] [uri "/wp-json/wp/v2/users"] [unique_id "aiydKEWhwriBCXIbpXkinwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack