๐บ๐ธ
TPI-Abuse
2026-06-16 08:47:02
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 138.197.145.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 138.197.145.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 04:46:56.132279 2026] [security2:error] [pid 26740:tid 26740] [client 138.197.145.244:48812] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.energycapitalinvestments.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.energycapitalinvestments.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajENgHW7fjIunCo6ujzcqwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 04:46:55
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 138.197.145.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 138.197.145.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 00:46:51.289941 2026] [security2:error] [pid 7978:tid 7978] [client 138.197.145.244:52982] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.justicehoward.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.justicehoward.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajDVO9py79DctVZN3fr3LQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 03:54:00
(10 hours ago)
[redacted] 138.197.145.244 - - [16/Jun/2026:05:53:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" ...
show more
[redacted] 138.197.145.244 - - [16/Jun/2026:05:53:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0"
[redacted] 138.197.145.244 - - [16/Jun/2026:05:53:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0"
[redacted] 138.197.145.244 - - [16/Jun/2026:05:53:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
[redacted] 138.197.145.244 - - [16/Jun/2026:05:53:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0"
[redacted] 138.197.145.244 - - [16/Jun/2026:05:53:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0"
[redacted] 138.197.145.244 - - [16/Jun/2026:05:53:58 +0200]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 06:20:27
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 138.197.145.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 138.197.145.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:20:20.116575 2026] [security2:error] [pid 4594:tid 4594] [client 138.197.145.244:38652] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.oakglenhouse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.oakglenhouse.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiulJADBu6SMWeSeQWY1-wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-04-30 11:31:58
(1 month ago)
Web attack from 138.197.145.244
Web App Attack
๐บ๐ธ
factor1
2026-04-15 08:11:58
(2 months ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
๐ท๐ด
INTEQ
2026-04-15 05:55:37
(2 months ago)
Web attack from 138.197.145.244
Web App Attack
๐ฉ๐ช
LRob.fr
2026-04-04 09:30:06
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-03-25 16:38:05
(2 months ago)
(PERMBLOCK) 138.197.145.244 (CA/Canada/Ontario/Toronto/-/[redacted]) has had more than 4 temp blocks
Hacking
๐ซ๐ฎ
Shaik Sai Meera
2026-03-25 05:05:12
(2 months ago)
IM360 WAF: Infectors: Suspicious access attempt (webshell)
Brute-Force
FTP Brute-Force
Open Proxy
๐ฉ๐ช
Hazzard
2026-03-24 17:14:33
(2 months ago)
(wordpress) Failed wordpress login from 138.197.145.244 (CA/Canada/Ontario/Toronto/-/[redacted]): ( ...
show more
(wordpress) Failed wordpress login from 138.197.145.244 (CA/Canada/Ontario/Toronto/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
Anonymous
2026-03-24 07:32:00
(2 months ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
๐บ๐ธ
lostswordfish.com
2026-03-24 06:34:03
(2 months ago)
Wordfence waf block on taussigtravel
Web App Attack
๐ต๐ฑ
IROK
2026-03-24 05:45:54
(2 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
๐ซ๐ท
masterguru
2026-03-23 09:40:38
(2 months ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (88020-197)
Hacking