Anonymous
2026-06-15 19:08:40
(2 hours ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-15 18:09:11
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 14:08:54.664478 2026] [security2:error] [pid 1747:tid 1747] [client 157.66.27.31:59828] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.badconsultingllc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.badconsultingllc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajA_tpWYPxPEdzVRxtLvJgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 15:19:06
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 11:18:52.173177 2026] [security2:error] [pid 11450:tid 11450] [client 157.66.27.31:35160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.peacecampus.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.peacecampus.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajAX3EyrlanY3CbqjcnBHAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 13:54:30
(7 hours ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-15 08:51:31
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 04:51:15.192636 2026] [security2:error] [pid 16073:tid 16073] [client 157.66.27.31:41626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "solarfarms.info"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-9A1KXnZXHn8B5vdli1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:48:20
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:48:16.223091 2026] [security2:error] [pid 28508:tid 28508] [client 157.66.27.31:40668] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.instalatoribucuresti.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.instalatoribucuresti.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-EELKcl_KYKG3AqboDSgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-15 02:38:58
(18 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:17:57
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:17:39.490328 2026] [security2:error] [pid 29964:tid 29964] [client 157.66.27.31:60982] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fatbastardcompetition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fatbastardcompetition.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai9Ss5O1P3gj4N9W_0w97gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:26:46
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:26:32.263379 2026] [security2:error] [pid 17987:tid 17987] [client 157.66.27.31:55430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.amespeak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.amespeak.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai9GuNvEZKsTyw6FGR7ZkwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:46:51
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:46:35.171652 2026] [security2:error] [pid 8986:tid 8986] [client 157.66.27.31:46776] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.technesa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.technesa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai8vS0PaIw3UfjLAVyGCnAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 11:06:43
(1 day ago)
[redacted] 157.66.27.31 - - [14/Jun/2026:13:05:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 157.66.27.31 - - [14/Jun/2026:13:05:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
[redacted] 157.66.27.31 - - [14/Jun/2026:13:05:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0"
[redacted] 157.66.27.31 - - [14/Jun/2026:13:05:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0"
[redacted] 157.66.27.31 - - [14/Jun/2026:13:06:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0"
[redacted] 157.66.27.31 - - [14/Jun/2026:13:06:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
[redacted] 157.66.27.31 - - [14/Jun/202
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 18:23:33
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.66.27.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 14:23:20.915588 2026] [security2:error] [pid 20925:tid 20925] [client 157.66.27.31:52352] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.feiz.church|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.feiz.church"] [uri "/wp-json/wp/v2/users"] [unique_id "ai2gGC2NM_spZBaZ4V99SwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Nerdscave Hosting
2026-06-13 14:20:53
(2 days ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
Anonymous
2026-06-13 11:40:48
(2 days ago)
[redacted] 157.66.27.31 - - [13/Jun/2026:13:40:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mo ...
show more
[redacted] 157.66.27.31 - - [13/Jun/2026:13:40:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0"
[redacted] 157.66.27.31 - - [13/Jun/2026:13:40:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:59.0) Gecko/20100101 Firefox/59.0"
[redacted] 157.66.27.31 - - [13/Jun/2026:13:40:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0"
[redacted] 157.66.27.31 - - [13/Jun/2026:13:40:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0"
[redacted] 157.66.27.31 - - [13/Jun/2026:13:40:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0"
[redacted] 157.66.27.31 - - [13/Jun/2026:13:40:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 261 "-" "M
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-13 08:07:05
(2 days ago)
Excessive 404/403 errors
Brute-Force