๐บ๐ธ
TPI-Abuse
2026-06-21 05:00:01
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 00:59:55.476870 2026] [security2:error] [pid 15573:tid 15573] [client 138.68.166.30:59446] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marinestorage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marinestorage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdvy0u3YEpbigHGXydaBwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 18:22:14
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 14:22:09.049140 2026] [security2:error] [pid 5988:tid 5988] [client 138.68.166.30:54282] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nypatriotcards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nypatriotcards.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajbaUVouMmeTi5j4jdJ1swAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 16:13:36
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 12:13:31.672460 2026] [security2:error] [pid 24287:tid 24287] [client 138.68.166.30:52040] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||speedgo.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "speedgo.mx"] [uri "/wp-json/wp/v2/users"] [unique_id "aja8K5sB35mRCslf6whDfAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 23:51:27
(2 days ago)
[redacted] 138.68.166.30 - - [19/Jun/2026:01:51:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "M ...
show more
[redacted] 138.68.166.30 - - [19/Jun/2026:01:51:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
[redacted] 138.68.166.30 - - [19/Jun/2026:01:51:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"
[redacted] 138.68.166.30 - - [19/Jun/2026:01:51:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0"
[redacted] 138.68.166.30 - - [19/Jun/2026:01:51:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0"
[redacted] 138.68.166.30 - - [19/Jun/2026:01:51:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 22:44:44
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 18:44:40.754599 2026] [security2:error] [pid 2410:tid 2410] [client 138.68.166.30:35514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honigcpa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajR02KOKD7A8-nOW-6b68gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 21:25:11
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 17:25:07.153065 2026] [security2:error] [pid 8634:tid 8634] [client 138.68.166.30:43886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.comicpreservation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.comicpreservation.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajRiM1abJRlgKfG7LBTNLAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 10:05:37
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 06:05:29.979059 2026] [security2:error] [pid 5889:tid 5889] [client 138.68.166.30:33060] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||shelbysmoak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "shelbysmoak.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajPC6X4Zw4AolyERl4vs-gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-18 03:57:39
(3 days ago)
(modsecurity) srv101 ModSecurity 138.68.166.30 (GB/United Kingdom/lon2.paulwebdesign.uk): 10 in the ...
show more
(modsecurity) srv101 ModSecurity 138.68.166.30 (GB/United Kingdom/lon2.paulwebdesign.uk): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 04:23:47
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 00:23:39.011382 2026] [security2:error] [pid 2925:tid 2925] [client 138.68.166.30:51274] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.comobarbershop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.comobarbershop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajIhS729qeZvWPFKhL3FTgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-17 03:02:10
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 21:24:43
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 17:24:37.185153 2026] [security2:error] [pid 3694:tid 3694] [client 138.68.166.30:55040] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jaragoodrich.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jaragoodrich.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajG_FSTDUEmlRGeOTw1rtQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 20:43:01
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 16:42:53.901016 2026] [security2:error] [pid 12994:tid 12994] [client 138.68.166.30:47432] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharawi-gum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajG1TVRxuiFqzvNfMwhInQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Kenshin869
2026-06-16 18:15:10
(4 days ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 16:11:39
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 12:11:33.732567 2026] [security2:error] [pid 28066:tid 28066] [client 138.68.166.30:35284] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.aandbnaturalfoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.aandbnaturalfoods.com"] [uri "/naturally/wp-json/wp/v2/users"] [unique_id "ajF1tQn6g5j7Zs5qdHDZqgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 14:39:54
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 138.68.166.30 (lon2.paulwebdesign.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 10:39:49.364971 2026] [security2:error] [pid 7706:tid 7706] [client 138.68.166.30:43972] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.psychiatryabuse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.psychiatryabuse.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajFgNUSKGc9XcWmngddmHAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack