🇺🇸
TPI-Abuse
2026-09-05 06:10:58
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 138.197.175.250 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 138.197.175.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 02:10:50.955863 2026] [security2:error] [pid 30746:tid 30746] [client 138.197.175.250:58644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||learnserve.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "learnserve.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apuyajwgDRBw7rXRlGHHTgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:19:06
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 138.197.175.250 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 138.197.175.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:19:00.168651 2026] [security2:error] [pid 13490:tid 13490] [client 138.197.175.250:33986] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||avvmarchetticollini.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "avvmarchetticollini.it"] [uri "/wp-json/wp/v2/users"] [unique_id "aps1xH1Y7A7RZ4Ye4Mr6tQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
xmission.com
2026-08-19 17:08:44
(2 weeks ago)
Blocked by UFW (TCP on 45166)
Source port: 443
TTL: 50
Packet length: 52
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 45166)
Source port: 443
TTL: 50
Packet length: 52
TOS: 0x08
This report (for 138.197.175.250) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇲🇽
octageeks.com
2026-08-19 04:42:39
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇲🇽
octageeks.com
2026-08-17 04:10:38
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
FeG Deutschland
2026-08-15 04:19:37
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇲🇽
octageeks.com
2026-08-15 04:11:54
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇪🇸
alferez
2026-08-12 17:46:32
(3 weeks ago)
Multiple WP Login Attack
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-08 22:57:58
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 138.197.175.250 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 138.197.175.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 18:57:43.921217 2026] [security2:error] [pid 200737:tid 200737] [client 138.197.175.250:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bradleybarefoot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bradleybarefoot.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ane0Z4StHQ2qa6o3QxB9jwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-06 21:10:22
(4 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇮🇳
evicky2002
2026-08-06 06:00:01
(4 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
neckaralb-admin.de
2026-08-05 10:23:24
(4 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
Site.eu
2026-08-04 23:58:42
(1 month ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇩🇪
Marc
2026-08-04 08:49:33
(1 month ago)
138.197.175.250 - - [04/Aug/2026:10:49:32 +0200] "GET /wp-login.php/wp-json/wp/v2/users?per_page=100 ...
show more
138.197.175.250 - - [04/Aug/2026:10:49:32 +0200] "GET /wp-login.php/wp-json/wp/v2/users?per_page=100&page=1&_fields=id,slug,name HTTP/2.0" 404 254 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" 138.197.175.250 - - [04/Aug/2026:10:49:32 +0200] "GET /wp-login.php/wp-json/wp/v2/users?per_page=50&_embed&_fields=id,slug,name HTTP/2.0" 404 43 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" 138.197.175.250 - - [04/Aug/2026:10:49:32 +0200] "GET /wp-login.php/wp-json/wp/v2/users?per_page=100&_fields=slug HTTP/2.0" 404 43 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
show less
Brute-Force
🇪🇸
masterguru
2026-08-04 07:42:15
(1 month ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack