🇺🇸
TPI-Abuse
2026-09-08 01:57:05
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:56:57.436919 2026] [security2:error] [pid 31770:tid 31770] [client 125.163.119.49:14512] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dietzengineers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dietzengineers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap9raX-p-X-r9PDX6t8TzAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:17:22
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:17:15.615647 2026] [security2:error] [pid 8842:tid 8842] [client 125.163.119.49:24378] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||diepeveen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "diepeveen.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap8byy-c8GcdibnXh5Jl6gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:36:06
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:35:56.838233 2026] [security2:error] [pid 14137:tid 14137] [client 125.163.119.49:21817] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||diegogamazo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "diegogamazo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap71_CvI0WnMK3kh7pp-pwAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 05:22:21
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:22:07.668871 2026] [security2:error] [pid 21609:tid 21609] [client 125.163.119.49:24757] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dick-schoonover.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dick-schoonover.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apz4f-uQg46HXS8uDP6VMAAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:41:37
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:41:29.694539 2026] [security2:error] [pid 29425:tid 29425] [client 125.163.119.49:27349] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dianogah.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dianogah.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apyMiWAUKKFaI77qb15fxwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 19:34:37
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:34:31.626157 2026] [security2:error] [pid 24488:tid 24488] [client 125.163.119.49:22848] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dianedanielsmanning.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dianedanielsmanning.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apxux9bzpv1PfhD84JOL9QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 17:41:57
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 13:41:51.265760 2026] [security2:error] [pid 23127:tid 23127] [client 125.163.119.49:12876] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dianamead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dianamead.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apxUX9oSEoOF2BhlsFa5OAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 15:09:50
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.119.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 11:09:45.097445 2026] [security2:error] [pid 7121:tid 7121] [client 125.163.119.49:50289] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||diamondtrailerserv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "diamondtrailerserv.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apwwue-JfzHo8SJxM6gaigAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-05 10:29:49
(3 days ago)
9.260 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2026-09-05 10:23:03
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET / HTTP/1.1
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-05 10:13:39
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-09-05 09:20:08
(3 days ago)
| [Dangerous/Indonesia] Aggressive IP 125.163.119.49 (~30 hits). Type: DoS Defender- Web server 400 ...
show more
| [Dangerous/Indonesia] Aggressive IP 125.163.119.49 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
🇮🇩
zam
2025-10-11 20:10:50
(10 months ago)
125.163.119.49 - - [11/Oct/2025:20:10:48 +0000] "GET /simple.php HTTP/1.1" 404 70935
Web App Attack
🇺🇸
agenciahypelab.com.br
2025-10-11 06:36:30
(10 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇹🇷
rtbh.com.tr
2025-10-10 20:09:17
(10 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force