๐บ๐ธ
TPI-Abuse
2026-08-26 13:44:58
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:44:54.063059 2026] [security2:error] [pid 9533:tid 9533] [client 135.236.141.150:3979] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rohanbyles.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rohanbyles.com.au"] [uri "/wp-json/wp/v2/users"] [unique_id "ao7t1uKC7_qcsvX7iuCGhQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 13:15:31
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:15:24.893809 2026] [security2:error] [pid 23694:tid 23694] [client 135.236.141.150:3301] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dixiegeek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao7m7GBkqRjzN7MWZmNP5AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-26 12:59:08
(8 hours ago)
angleseaarthouse.com.au:443 135.236.141.150 - - [26/Aug/2026:22:59:05 +1000] "GET /?author=2 HTTP/1. ...
show more
angleseaarthouse.com.au:443 135.236.141.150 - - [26/Aug/2026:22:59:05 +1000] "GET /?author=2 HTTP/1.1" 404 191298 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-08-26 12:58:47
(8 hours ago)
2026-08-26T14:58:45.466459+02:00 aion wordpress[2815737]: Blocked user enumeration attempt from 135. ...
show more
2026-08-26T14:58:45.466459+02:00 aion wordpress[2815737]: Blocked user enumeration attempt from 135.236.141.150
...
show less
Hacking
Brute-Force
Anonymous
2026-08-26 12:40:07
(8 hours ago)
2026-08-26T12:40:07.201891+00:00 instance-20260804-1025 wordpress(jumarpab.co)[609313]: Blocked user ...
show more
2026-08-26T12:40:07.201891+00:00 instance-20260804-1025 wordpress(jumarpab.co)[609313]: Blocked user enumeration attempt from 135.236.141.150
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 11:07:38
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:07:33.321274 2026] [security2:error] [pid 17967:tid 17983] [client 135.236.141.150:3003] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clearwaterpumpservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clearwaterpumpservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao7I9Qf5XBXhfIF5T1bnsAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-26 10:28:28
(10 hours ago)
[26/Aug/2026:13:28:28 +0300] -- 135.236.141.150 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp ...
show more
[26/Aug/2026:13:28:28 +0300] -- 135.236.141.150 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/ldlms/v1/users?per_page=100&_fields=user_login HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:26:06
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:25:58.905764 2026] [security2:error] [pid 9665:tid 9665] [client 135.236.141.150:2992] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dvdmasters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dvdmasters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6_NrQA-gfb7VAGiq8lxwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-08-26 09:22:55
(11 hours ago)
Web App Attack
Web App Attack
๐ฉ๐ช
LRob
2026-08-26 07:47:38
(13 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-26 07:47 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 07:16:59
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:16:55.293457 2026] [security2:error] [pid 22485:tid 22485] [client 135.236.141.150:4162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.escapegeorgesrouquier.williamgilcher.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.escapegeorgesrouquier.williamgilcher.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ao6S53VvLaHd4Mf4jKV_DAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 06:50:20
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 02:50:13.964796 2026] [security2:error] [pid 2142:tid 2142] [client 135.236.141.150:6630] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||twincitytn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "twincitytn.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6Mpe_koR63EqGS7h1iBAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 06:39:57
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 06:25:57
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.236.141.150 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 02:25:52.939296 2026] [security2:error] [pid 31596:tid 31596] [client 135.236.141.150:4163] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blacksheepoffroad.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6G8ARzEZ8MQjqCFdUwhwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-12 04:13:24
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack