🇺🇸
TPI-Abuse
2026-09-04 20:42:47
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:42:42.626030 2026] [security2:error] [pid 3106:tid 3185] [client 125.163.117.217:40676] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dhsandberg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dhsandberg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apstQmKvq6Tz6axckhMISgAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 17:02:47
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 13:02:41.016778 2026] [security2:error] [pid 17220:tid 17220] [client 125.163.117.217:7022] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dhappraisalservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dhappraisalservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apr5sfg72xCwVpr4t2qO9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:31:48
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:31:44.763176 2026] [security2:error] [pid 4691:tid 4691] [client 125.163.117.217:28786] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dgroupsa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dgroupsa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aprWUGzY--WJ6ctbUGvxDAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-09-04 14:11:39
(1 day ago)
Web App Attack
Web App Attack
🇩🇪
LRob
2026-09-04 13:47:24
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /xmlrpc.php | 2026-09-04 13:47 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:46:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:46:49.910515 2026] [security2:error] [pid 6607:tid 6607] [client 125.163.117.217:10750] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dezignz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dezignz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apppWX4kqLKUlltSfa0mAAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 06:41:22
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:08:00
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:07:53.255224 2026] [security2:error] [pid 19573:tid 19637] [client 125.163.117.217:65418] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||deyyoungart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "deyyoungart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "appgOZmVvP1SYC0k1lCvQgAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-04 03:26:08
(1 day ago)
Scanning for web/db/file exploits on www.dewijs-3d.com
SQL Injection
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:11:37
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:11:31.435097 2026] [security2:error] [pid 3562:tid 3562] [client 125.163.117.217:7233] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||deweysearch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "deweysearch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apo24w48C0de2ohtT9f44AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 01:42:35
(1 day ago)
[03/Sep/2026:21:42:34.870761 --0400] apoiCrp3gtat9kaP3lt5OwAAAQA 125.163.117.217 46912 205.233.18.17 ...
show more
[03/Sep/2026:21:42:34.870761 --0400] apoiCrp3gtat9kaP3lt5OwAAAQA 125.163.117.217 46912 205.233.18.17 7081
[03/Sep/2026:21:42:34.870927 --0400] apoiCu2LUNsX7oZ@-msmdQAAAYY 125.163.117.217 46922 205.233.18.17 7081
[03/Sep/2026:21:42:34.871187 --0400] apoiCrp3gtat9kaP3lt5PAAAAQM 125.163.117.217 46934 205.233.18.17 7081
[03/Sep/2026:21:42:34.871454 --0400] apoiCrp3gtat9kaP3lt5OgAAARM 125.163.117.217 46908 205.233.18.17 7081
[03/Sep/2026:21:42:34.872536 --0400] apoiCkItTgq1-gscN96BUQAAAEE 125.163.117.217 46944 205.233.18.17 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 01:24:36
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:24:32.442582 2026] [security2:error] [pid 11127:tid 11127] [client 125.163.117.217:28980] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dodojuice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dodojuice.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apod0EKKZTAl1rr5t9ew1AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 00:55:49
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:29:49
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:29:39.230392 2026] [security2:error] [pid 17489:tid 17489] [client 125.163.117.217:15590] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doctorspainmanagement.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doctorspainmanagement.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apn00xYKMyzLNw15_WEk_wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 17:28:29
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.117.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:28:21.914448 2026] [security2:error] [pid 14730:tid 14730] [client 125.163.117.217:21807] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doctoredwinalvarez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doctoredwinalvarez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apmuNY310IMGgGQnLw2X1gAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack