🇺🇸
nationaleventpros.com
2026-09-05 05:38:14
(19 hours ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 03:03:41
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 23:03:35.627806 2026] [security2:error] [pid 1973:tid 1973] [client 157.22.124.48:51345] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lopansri.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lopansri.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apuGh0nBzD9qAeYBwmHlUwAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
OceanTreasure
2026-09-04 19:35:08
(1 day ago)
tcp/443; WordPress XML-RPC brute force attempt: "POST /xmlrpc.php" @ 2026-09-04T19:27:46Z [proxy]
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-08-24 19:01:26
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 15:01:18.743406 2026] [security2:error] [pid 26350:tid 26350] [client 157.22.124.48:42873] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coroneta.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coroneta.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoyU_q9J-c-CpRTWGLNL6gAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-08-20 17:13:28
(2 weeks ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-08-19 18:58:16
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 14:58:12.072782 2026] [security2:error] [pid 25610:tid 25610] [client 157.22.124.48:41387] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theproducers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theproducers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoX8xIwb_tS8Ly0ek9-ChQAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 22:18:57
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 18:18:53.086897 2026] [security2:error] [pid 21632:tid 21632] [client 157.22.124.48:44699] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gisur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gisur.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoTaTYYLPFYAX3qi1mbg9AAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 15:19:27
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:19:23.953631 2026] [security2:error] [pid 961998:tid 961998] [client 157.22.124.48:34289] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rockymtnfire.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rockymtnfire.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amd2-xYW3buLeT7r4jtQuwAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
Coolnagour
2026-07-18 18:02:21
(1 month ago)
http-probing: /xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-07-14 11:06:42
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.124.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 07:06:38.405204 2026] [security2:error] [pid 23841:tid 23841] [client 157.22.124.48:23495] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||digifonics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "digifonics.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alYYPldG9yApuAPxLqZ-OAAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-07-02 04:18:47
(2 months ago)
tilellit/wp-armour-ban
Hacking
🇫🇷
Tilellit.PRO
2026-06-29 16:03:23
(2 months ago)
Fail2Ban banned 157.22.124.48 for security violations in jail wp-armour. Log: 2026/06/29 16:03:23 [e ...
show more
Fail2Ban banned 157.22.124.48 for security violations in jail wp-armour. Log: 2026/06/29 16:03:23 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 157.22.124.48 | Target: wplogin" , client: 157.22.124.48, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇫🇷
Tilellit.PRO
2026-06-28 09:13:18
(2 months ago)
Fail2Ban banned 157.22.124.48 for security violations in jail wp-armour. Log: 2026/06/28 09:13:18 [e ...
show more
Fail2Ban banned 157.22.124.48 for security violations in jail wp-armour. Log: 2026/06/28 09:13:18 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 157.22.124.48 | Target: wplogin" , client: 157.22.124.48, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇨🇭
backslash
2026-06-27 09:33:00
(2 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇫🇷
Tilellit.PRO
2026-06-27 05:20:14
(2 months ago)
Fail2Ban banned 157.22.124.48 for security violations in jail wp-armour. Log: 2026/06/27 05:20:14 [e ...
show more
Fail2Ban banned 157.22.124.48 for security violations in jail wp-armour. Log: 2026/06/27 05:20:14 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 157.22.124.48 | Target: wplogin" , client: 157.22.124.48, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam