๐บ๐ธ
TPI-Abuse
2026-06-15 23:37:34
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.22.47.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.47.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 19:37:29.270486 2026] [security2:error] [pid 12586:tid 12586] [client 157.22.47.34:57349] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thecalls.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thecalls.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajCMucVgw_ouaz8RjKUquwAAAHY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-06-14 19:33:47
(2 days ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-07 17:36:33
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 157.22.47.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.47.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 13:36:26.793092 2026] [security2:error] [pid 3190:tid 3190] [client 157.22.47.34:44691] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||austli.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "austli.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiWsGnJaJXt_GYzE6erdbQAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 14:20:34
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 157.22.47.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.47.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:20:28.778147 2026] [security2:error] [pid 27715:tid 27715] [client 157.22.47.34:31435] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zavion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zavion.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiGJrEavQz523b1EvIh_-wAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-06-01 23:16:53
(2 weeks ago)
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 14:13:33
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 157.22.47.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.47.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 10:13:25.305597 2026] [security2:error] [pid 20601:tid 20601] [client 157.22.47.34:42197] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pseudospace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pseudospace.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahrwhXVxNqCKPfAQzyO5wgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mind5t0rm
2026-05-09 16:16:00
(1 month ago)
(XMLRPC) WP XMLPRC Attack 157.22.47.34 (SC/Seychelles/-): 3 in the last 3600 secs; Ports: *; Directi ...
show more
(XMLRPC) WP XMLPRC Attack 157.22.47.34 (SC/Seychelles/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 157.22.47.34 - - [09/May/2026:23:15:57 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "Wget/1.21.4"
157.22.47.34 - - [09/May/2026:23:15:57 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "curl/7.88.1"
157.22.47.34 - - [09/May/2026:23:15:58 +0700] "POST /xmlrpc.php HTTP/2.0" 403 154 "-" "Wget/1.21.4"
show less
Port Scan
๐บ๐ธ
agenciahypelab.com.br
2026-04-17 14:43:42
(1 month ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
Anonymous
2026-04-13 06:25:55
(2 months ago)
2026-04-13T08:25:55.771797+02:00 zanati wp(www.sahpa.co.za)[1450102]: Blocked authentication attempt ...
show more
2026-04-13T08:25:55.771797+02:00 zanati wp(www.sahpa.co.za)[1450102]: Blocked authentication attempt for [email protected] from 157.22.47.34
...
show less
Web App Attack