🇺🇸
TPI-Abuse
2026-09-04 22:24:32
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:24:28.923059 2026] [security2:error] [pid 13961:tid 13966] [client 123.20.244.154:57204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chaoticperception.cynosureinternetservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chaoticperception.cynosureinternetservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aptFHGMPq6Xc4uinwBNDXgAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:51:01
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:50:55.468891 2026] [security2:error] [pid 7168:tid 7168] [client 123.20.244.154:60004] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.thepotteriesmesilla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.thepotteriesmesilla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aps9P1RpTRQyZnS1sqHRXQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
LRob
2026-09-04 20:28:48
(14 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-04 20:28 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:22:49
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:22:42.265723 2026] [security2:error] [pid 11154:tid 11154] [client 123.20.244.154:54370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.escapegeorgesrouquier.williamgilcher.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.escapegeorgesrouquier.williamgilcher.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apsokgV-w2SBLdKIqcgMzwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:58:21
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:58:16.289069 2026] [security2:error] [pid 18537:tid 18537] [client 123.20.244.154:40338] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||luxandunion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "luxandunion.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apsi2EfdZ8y339Z4ljRRcgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:19:30
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:19:22.288519 2026] [security2:error] [pid 5699:tid 5699] [client 123.20.244.154:48028] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grasslakepizzatime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grasslakepizzatime.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apsZuuSYUYeFySAtKw5YYQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
conseilgouz
2026-09-04 19:04:05
(15 hours ago)
hae-7 : Trying access unauthorized files/dir=>/wp-json/wp/v2/users/me
Hacking
🇺🇸
TPI-Abuse
2026-09-04 18:35:49
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:35:42.630143 2026] [security2:error] [pid 15224:tid 15224] [client 123.20.244.154:42790] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.calgaryhottubsale.wholesalelivelobsters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.calgaryhottubsale.wholesalelivelobsters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apsPfuEc-MB4Au_bb5uUegAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-04 18:27:59
(16 hours ago)
123.20.244.154 - - [04/Sep/2026:16:09:44 +0200] "GET /rss/ HTTP/2.0" 301 423 "-" "Mozilla/5.0 (Windo ...
show more
123.20.244.154 - - [04/Sep/2026:16:09:44 +0200] "GET /rss/ HTTP/2.0" 301 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
123.20.244.154 - - [04/Sep/2026:16:09:46 +0200] "GET /feed/ HTTP/2.0" 200 479 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
123.20.244.154 - - [04/Sep/2026:16:12:38 +0200] "POST /xmlrpc.php HTTP/2.0" 403 374 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
123.20.244.154 - - [04/Sep/2026:19:49:29 +0200] "GET /wp-sitemap-users-1.xml HTTP/2.0" 301 359 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
123.20.244.154 - - [04/Sep/2026:19:49:31 +0200] "GET /wp-sitemap-users-1.xml HTTP/2.0" 404 41591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.
show less
Web App Attack
Hacking
🇩🇪
LRob
2026-09-04 18:15:52
(16 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-04 18:15 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:12:31
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:12:24.575811 2026] [security2:error] [pid 12833:tid 12833] [client 123.20.244.154:52016] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paulshorrock.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paulshorrock.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apsKCFioWxgDTIvzuaDsmQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:45:33
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:45:25.953225 2026] [security2:error] [pid 24846:tid 24846] [client 123.20.244.154:55436] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||km.digitalsolutions.help|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "km.digitalsolutions.help"] [uri "/wp-json/wp/v2/users"] [unique_id "apr1pbdy4VU5R0OKKmlHNQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:42:33
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:42:29.172841 2026] [security2:error] [pid 23005:tid 23097] [client 123.20.244.154:52670] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||streamwriters.com.hdtv55.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "streamwriters.com.hdtv55.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aprm5bbRlZcG9IeHctYE0QAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:33:46
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 123.20.244.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:33:42.395735 2026] [security2:error] [pid 29919:tid 29919] [client 123.20.244.154:52044] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wealthsec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wealthsec.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aprWxn4mlw86jP-KPyKUAgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 12:55:44
(21 hours ago)
[04/Sep/2026:15:55:44 +0300] -- 123.20.244.154 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[04/Sep/2026:15:55:44 +0300] -- 123.20.244.154 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/wc/v3/customers?per_page=100&_fields=username,email HTTP/1.1
show less
Bad Web Bot
Web App Attack