Anonymous
2025-05-02 05:34:54
(2 weeks ago)
Trawling for Open Source CMS installs
Hacking
Brute-Force
TPI-Abuse
2025-05-02 03:44:22
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 01 23:44:15.087910 2025] [security2:error] [pid 1490331:tid 1490331] [client 143.198.212.55:54572] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.yogawithbubba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.yogawithbubba.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBQ_jxNDLtQ1TBSZMIvpmwAAAA0"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-02 01:34:37
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 01 21:34:30.563901 2025] [security2:error] [pid 1356996:tid 1356996] [client 143.198.212.55:57985] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zacharypowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zacharypowers.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBQhJuL-eVhwsp9Kv68UQAAAAB8"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-01 01:47:27
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 21:47:23.599781 2025] [security2:error] [pid 20997:tid 20997] [client 143.198.212.55:63710] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wurkroom.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wurkroom.biz"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBLSq9i069PHvyFRyMW5owAAABg"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-30 09:02:11
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 05:02:06.617449 2025] [security2:error] [pid 15391:tid 15391] [client 143.198.212.55:54518] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wsffjatc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wsffjatc.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBHnDn9AdAHmaYl0rk5YRwAAAA8"] show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-30 08:43:18
(2 weeks ago)
Malicious activity detected
Hacking
Web App Attack
TPI-Abuse
2025-04-30 07:57:10
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 03:57:03.366503 2025] [security2:error] [pid 3176884:tid 3176884] [client 143.198.212.55:65320] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.wpcoc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.wpcoc.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBHXz8QsBnzcP1SyTKaxnQAAABg"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-30 05:47:58
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 01:47:54.562511 2025] [security2:error] [pid 691789:tid 691789] [client 143.198.212.55:53467] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wetlizarddiveteam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wetlizarddiveteam.com"] [uri "/wp/wp-json/wp/v2/users/"] [unique_id "aBG5io7WQUNGT2R3-z5U0gAAAAM"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-30 02:48:05
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 22:47:57.138682 2025] [security2:error] [pid 28046:tid 28046] [client 143.198.212.55:51682] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webuychesterfieldhouses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webuychesterfieldhouses.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBGPXamloLWYiuvB9uSZZgAAABI"] show less
Brute-Force
Bad Web Bot
Web App Attack
iNetWorker
2025-04-30 02:33:39
(2 weeks ago)
trolling for resource vulnerabilities
Web App Attack
TPI-Abuse
2025-04-30 01:13:54
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 21:13:50.489110 2025] [security2:error] [pid 5232:tid 5232] [client 143.198.212.55:55430] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wbtndesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wbtndesigns.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBF5TnceaKND-89g5ztPRQAAAAo"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-29 06:09:46
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 02:09:43.112294 2025] [security2:error] [pid 807571:tid 807571] [client 143.198.212.55:51743] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.waterjetsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.waterjetsolutions.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBBtJ-imV7EcgGtsRserNAAAAA8"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-29 05:41:06
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 01:40:57.923157 2025] [security2:error] [pid 19817:tid 19821] [client 143.198.212.55:55694] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wasula.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wasula.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "aBBmaYsaGPYONuJ6KByuegAAAII"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-29 04:32:07
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 00:32:00.961453 2025] [security2:error] [pid 2230071:tid 2230071] [client 143.198.212.55:58861] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.virtualmediamasters.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.virtualmediamasters.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBBWQAT72_r7Ha6INljB9wAAAAI"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-29 03:37:19
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Por ... show more (mod_security) mod_security (id:225170) triggered by 143.198.212.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 28 23:37:13.457097 2025] [security2:error] [pid 2098:tid 2197] [client 143.198.212.55:55669] [client 143.198.212.55] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vinylnotespodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vinylnotespodcast.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBBJabZIByIlV9X2iVjFQwAAAQE"] show less
Brute-Force
Bad Web Bot
Web App Attack