🇺🇸
TPI-Abuse
2026-09-05 19:15:17
(7 minutes ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:15:12.163518 2026] [security2:error] [pid 22566:tid 22566] [client 144.31.2.14:37804] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goatedlottosecrets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goatedlottosecrets.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apxqQDySILRBd39FI1V1YwAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 18:59:13
(23 minutes ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 14:59:07.244371 2026] [security2:error] [pid 7912:tid 7912] [client 144.31.2.14:40836] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||beatthegm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "beatthegm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apxme-4XIkvEN6v3LIFRqgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-05 18:51:13
(31 minutes ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 144.31.2.14 (PL/Poland/s270770.love-is.nexus): ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 144.31.2.14 (PL/Poland/s270770.love-is.nexus): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 144.31.2.14 - - [05/Sep/2026:20:51:09 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12043 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36" "-" host=emmeccipubblicita.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-05 18:19:35
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 14:19:28.283440 2026] [security2:error] [pid 27765:tid 27776] [client 144.31.2.14:35054] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||maryschalkdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "maryschalkdesign.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apxdMDzU5AZTCgItg3f4zQAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nyt
2026-09-05 18:07:20
(1 hour ago)
WP Author Enumeration, WP User Enumeration
Web App Attack
🇩🇪
maxpower
2026-09-05 17:47:57
(1 hour ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 144.31.2.14 (PL/Poland/s270770.love-is.nexus): ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 144.31.2.14 (PL/Poland/s270770.love-is.nexus): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 144.31.2.14 - - [05/Sep/2026:19:47:54 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 11895 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36" "-" host=iampieriarredamenti.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-05 17:36:47
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 13:36:43.731086 2026] [security2:error] [pid 32094:tid 32094] [client 144.31.2.14:47350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||localpetsitters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "localpetsitters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apxTK7OlqR7njJIkdqItZAAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-05 17:31:57
(1 hour ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 144.31.2.14 (PL/Poland/s270770.love-is.nexus): ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 144.31.2.14 (PL/Poland/s270770.love-is.nexus): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 144.31.2.14 - - [05/Sep/2026:19:31:55 +0200] "GET /wp-json/wp/v2/users HTTP/2.0" 200 4727 "https://www.google.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36" "144.31.2.14" host=digiampaolosrl.it
show less
Port Scan
🇫🇷
ELYAZ
2026-09-05 17:29:53
(1 hour ago)
(y3) Failed access -byebye- from 144.31.2.14 (PL/Poland/s270770.love-is.nexus): (CF_ENABLE)
Hacking
🇺🇸
TPI-Abuse
2026-09-05 17:18:25
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 13:18:17.735293 2026] [security2:error] [pid 22007:tid 22020] [client 144.31.2.14:44844] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||planmytrust.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "planmytrust.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apxO2YPfFZMk0ckPyjXEbgAAAUk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 17:12:47
(2 hours ago)
2026-09-05T17:12:46.938752+00:00 instance-20260804-1025 wordpress(cazseguros.com)[1709673]: Immediat ...
show more
2026-09-05T17:12:46.938752+00:00 instance-20260804-1025 wordpress(cazseguros.com)[1709673]: Immediately block connections from 144.31.2.14
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 16:55:40
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 12:55:33.964900 2026] [security2:error] [pid 27217:tid 27217] [client 144.31.2.14:33056] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||judithcaldwell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "judithcaldwell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apxJhRPhxpEfpN7tX-uh8wAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 16:39:29
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 12:39:23.843010 2026] [security2:error] [pid 31750:tid 31750] [client 144.31.2.14:56324] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flybits.co.uk|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flybits.co.uk"] [uri "/wp-json/wp/v2/users"] [unique_id "apxFu8wNn7e0PFs3eK1daQAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 16:19:43
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 12:19:37.876038 2026] [security2:error] [pid 27906:tid 27906] [client 144.31.2.14:44876] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grandpont-house.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grandpont-house.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apxBGV3F671VWioB_Ryz4QAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 16:01:00
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 144.31.2.14 (s270770.love-is.nexus): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 12:00:53.811836 2026] [security2:error] [pid 27650:tid 27650] [client 144.31.2.14:33730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ohanameetup.party|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ohanameetup.party"] [uri "/wp-json/wp/v2/users"] [unique_id "apw8tV4GBKg53bCv5AURHAAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack