πΊπΈ
TPI-Abuse
2026-05-19 01:12:19
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 21:12:15.682933 2026] [security2:error] [pid 22513:tid 22513] [client 103.159.52.7:55464] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||soereng.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "soereng.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agu475d0LCBjScdCL046lwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-05-18 18:25:55
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
RLDD
2026-05-18 15:34:15
(3 weeks ago)
WP login attempts -nov
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-18 08:22:10
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 04:22:02.621144 2026] [security2:error] [pid 15798:tid 15798] [client 103.159.52.7:40096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agrMKlAu79gZx0CODCb2mgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
tilellit.pro
2026-05-17 20:37:40
(3 weeks ago)
Fail2Ban banned 103.159.52.7 for security violations in jail wp-armour. Log: 2026/05/17 20:37:39 [er ...
show more
Fail2Ban banned 103.159.52.7 for security violations in jail wp-armour. Log: 2026/05/17 20:37:39 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 103.159.52.7 | Target: wplogin" , client: 103.159.52.7, server: [REDACTED], request: "POST /wp-login.php HTTP/2.0", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
πΊπΈ
TPI-Abuse
2026-05-17 11:00:53
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 07:00:48.195190 2026] [security2:error] [pid 25164:tid 25164] [client 103.159.52.7:42640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inquisitivequincie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inquisitivequincie.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agmf4DSv0RcZH82-HtrAVgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
octageeks.com
2026-05-17 04:10:54
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
π²πΉ
Malta
2026-05-17 03:08:56
(3 weeks ago)
103.159.52.7 - - [17/May/2026:05:08:56 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linux ...
show more
103.159.52.7 - - [17/May/2026:05:08:56 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-17 02:58:26
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 22:58:19.936632 2026] [security2:error] [pid 14096:tid 14249] [client 103.159.52.7:57492] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgementz.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgementz.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agkuy74REvLEJQarNEZ7ywAAAhY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
1gz
2026-05-17 02:36:59
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-16 21:44:29
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 17:44:24.603690 2026] [security2:error] [pid 19002:tid 19002] [client 103.159.52.7:46624] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puckerbackbikini.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puckerbackbikini.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agjlOIFUWJJLfdCf_puQFwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Ba-Yu
2026-05-16 16:28:34
(4 weeks ago)
WordPress bruteforce
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
π«π·
masterguru
2026-05-16 16:03:04
(4 weeks ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.159.52.7 (VN/Vietnam/-): 1 in the last 36 ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.159.52.7 (VN/Vietnam/-): 1 in the last 3600 secs (0-197)
show less
Hacking
π«π·
masterguru
2026-05-16 14:23:41
(4 weeks ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.159.52.7 (VN/Vietnam/-): 1 in the last 36 ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.159.52.7 (VN/Vietnam/-): 1 in the last 3600 secs (0-196)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-05-16 06:08:33
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.159.52.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 02:08:27.363416 2026] [security2:error] [pid 13768:tid 13768] [client 103.159.52.7:37442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||beirutbazar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "beirutbazar.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aggJ22b7ze2KaXLBYUv5-wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack