๐ฉ๐ช
LRob.fr
2026-06-17 11:00:09
(4 minutes ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 09:16:50
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 05:16:42.878908 2026] [security2:error] [pid 27931:tid 27931] [client 124.123.19.5:48190] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||high5-vr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "high5-vr.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajJl-jbF0qnMFmlHXiwocgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 08:50:50
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 04:50:46.298098 2026] [security2:error] [pid 24686:tid 24686] [client 124.123.19.5:45038] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nearfieldchrist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nearfieldchrist.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajJf5pBNhWObruVdfLQCugAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 08:21:19
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 04:21:15.646555 2026] [security2:error] [pid 11180:tid 11180] [client 124.123.19.5:35434] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dev.jeanniemorrislaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dev.jeanniemorrislaw.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajJY-5rGSjXIWA3HtUkc6wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-17 08:12:05
(2 hours ago)
Wordfence waf block on uvfousor WPIDD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 07:53:09
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 03:53:01.627322 2026] [security2:error] [pid 29636:tid 29636] [client 124.123.19.5:41220] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arthuryeung.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arthuryeung.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajJSXc2ySfYvKuhOHfyRJgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 06:07:02
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 02:06:55.220507 2026] [security2:error] [pid 20584:tid 20584] [client 124.123.19.5:51174] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||garanta.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "garanta.co"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajI5f3dpcCNoaGdMSm3v2AAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-06-17 05:35:37
(5 hours ago)
WP Exploit attempt. Evidence: [REDACTED_DOMAIN]:443 124.123.19.5 - - [17/Jun/2026:06:35:31 +0100] PO ...
show more
WP Exploit attempt. Evidence: [REDACTED_DOMAIN]:443 124.123.19.5 - - [17/Jun/2026:06:35:31 +0100] POST /wp-login.php HTTP/2.0 200 5416 https://[REDACTED_DOMAIN]/wp-login.php Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 04:13:15
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 00:13:07.743193 2026] [security2:error] [pid 15157:tid 15157] [client 124.123.19.5:49128] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||anchor07.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "anchor07.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajIe02sbgO6Dqhn1v99D7gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-06-17 03:52:57
(7 hours ago)
WordPress bruteforce
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 02:37:16
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 124.123.19.5 (124.123.19.5.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 22:37:08.490841 2026] [security2:error] [pid 29422:tid 29422] [client 124.123.19.5:36446] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||constructionloansfunding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "constructionloansfunding.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajIIVGkrn4e63JFR549i0AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-17 01:20:22
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-17 00:53:46
(10 hours ago)
(y4) Failed scan -byebye- from 124.123.19.5 (IN/India/-): (CF_ENABLE)
Hacking
๐ซ๐ฎ
stinpriza
2026-06-17 00:50:09
(10 hours ago)
Web App Attack
Web App Attack
๐ฉ๐ช
Hazzard
2026-06-17 00:49:31
(10 hours ago)
(wordpress) Failed wordpress login from 124.123.19.5 (IN/India/-/-/124.123.19.5.actcorp.in/[redacted ...
show more
(wordpress) Failed wordpress login from 124.123.19.5 (IN/India/-/-/124.123.19.5.actcorp.in/[redacted]): (CF_ENABLE)
show less
Brute-Force