๐บ๐ธ
TPI-Abuse
2026-06-16 22:02:17
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 18:02:12.559684 2026] [security2:error] [pid 25011:tid 25011] [client 103.63.111.138:39500] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.margroberts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.margroberts.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajHH5OtYqkdAMHH2VOGbOAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 07:28:00
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 03:27:51.339460 2026] [security2:error] [pid 3367:tid 3367] [client 103.63.111.138:55556] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ruthbalser.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ruthbalser.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajD692ILqKLiKu5PB0pUogAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 13:20:55
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 09:20:50.964431 2026] [security2:error] [pid 25948:tid 25948] [client 103.63.111.138:39742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.stop902.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.stop902.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_8Mo5-qEQnC22qKER5GAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 15:29:00
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:28:53.644006 2026] [security2:error] [pid 23237:tid 23237] [client 103.63.111.138:36796] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.scswat.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.scswat.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai7Itf9Tuu6zQBtpPof0_wAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 10:24:48
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:24:42.603438 2026] [security2:error] [pid 29124:tid 29124] [client 103.63.111.138:42742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.allotrope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.allotrope.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai6Bahm8ZBfS72odu7gB9gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-13 13:15:41
(4 days ago)
Blocked by CSF 13 firewall - Rule: VN/Vietnam/static.cmcti.vn
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 01:50:53
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 21:50:46.360526 2026] [security2:error] [pid 23074:tid 23074] [client 103.63.111.138:56774] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adona.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adona.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aiy3dssLThzt0QR8EHWHigAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 12:20:29
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 08:20:21.959471 2026] [security2:error] [pid 5519:tid 5519] [client 103.63.111.138:41090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sizefinder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sizefinder.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiv5hb-zspjm_h8M8Dp0ZwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 18:01:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 14:01:15.945126 2026] [security2:error] [pid 31916:tid 31916] [client 103.63.111.138:45208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.majesticsolutions.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.majesticsolutions.co"] [uri "/wp-json/wp/v2/users"] [unique_id "aimma4YXN8JoCCKvprD3RAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 08:33:40
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 04:33:35.916825 2026] [security2:error] [pid 31538:tid 31538] [client 103.63.111.138:33388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.thesteeldrumman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.thesteeldrumman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aikhX9hoPFVplVjMLwYlSQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 23:15:41
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 19:15:36.085970 2026] [security2:error] [pid 8927:tid 8927] [client 103.63.111.138:42212] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tarekshohaieb.online|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tarekshohaieb.online"] [uri "/wp-json/wp/v2/users"] [unique_id "aiiemIpz2MxaQYWFhc4JfgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 19:41:05
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 15:40:57.996888 2026] [security2:error] [pid 11530:tid 11530] [client 103.63.111.138:60420] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||campnecon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "campnecon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aihsSd9pivPuhGI2ZOmqmgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-09 18:31:08
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 17:52:40
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 103.63.111.138 (static.cmcti.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 13:52:35.651212 2026] [security2:error] [pid 23950:tid 23985] [client 103.63.111.138:56408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.asetiadi.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.asetiadi.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aihS44KUcWsIdWwzKu_tFgAAAcY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Dolphi
2026-06-09 00:00:08
(1 week ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack