๐บ๐ธ
TPI-Abuse
2026-08-31 07:50:14
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:50:09.733626 2026] [security2:error] [pid 6689:tid 6689] [client 159.203.30.197:41906] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bervick.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bervick.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUyMXk1cm8okewXtpAhRAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 07:02:54
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:02:46.484426 2026] [security2:error] [pid 13252:tid 13252] [client 159.203.30.197:44166] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kerrywood.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kerrywood.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUnFpKIW2qqM8yuxu3JDwAAAAQ"], referer: http://kerrywood.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-08-31 05:37:51
(4 hours ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 04:58:41
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 00:58:36.315665 2026] [security2:error] [pid 21366:tid 21366] [client 159.203.30.197:48684] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||davidharrisgriffith.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "davidharrisgriffith.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUJ_AMLVTtIpCp4hKw1RAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 03:00:26
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:00:20.458434 2026] [security2:error] [pid 15500:tid 15509] [client 159.203.30.197:46268] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inal.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inal.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apTuRGfffb1shkAVnPeAFgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
seniorlinuxadmin
2026-08-31 02:30:57
(7 hours ago)
159.203.30.197 - - [30/Aug/2026:13:47:20 +0100] "GET /wp-login.php HTTP/2.0" 404 158 "-" "Mozilla/5. ...
show more
159.203.30.197 - - [30/Aug/2026:13:47:20 +0100] "GET /wp-login.php HTTP/2.0" 404 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
show less
Port Scan
Web App Attack
๐บ๐ธ
ph
2026-08-31 02:24:41
(7 hours ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 01:44:41
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 21:44:33.683162 2026] [security2:error] [pid 31393:tid 31393] [client 159.203.30.197:38942] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tckgbookkeeping.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tckgbookkeeping.biz"] [uri "/wp-json/wp/v2/users"] [unique_id "apTcgSulvccCRrQ5Qy7dAwAAABI"], referer: http://arogun.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
joe-abuse
2026-08-31 01:41:39
(8 hours ago)
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 1 ...
show more
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 19:00:23. Events: 1. Reported by ipdb-security/fitzgerald.eu
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 00:43:20
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 20:43:15.568696 2026] [security2:error] [pid 30785:tid 30785] [client 159.203.30.197:57684] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||texaslawman.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "texaslawman.net"] [uri "/wp-json/wp/v2/users"] [unique_id "apTOIxMBv8z6ONHYII_IfAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 00:22:46
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 20:22:42.685153 2026] [security2:error] [pid 3257:tid 3257] [client 159.203.30.197:45960] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newmooncafe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newmooncafe.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apTJUkADaFwTJxPffaoWzwAAAB0"], referer: http://newmooncafe.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-08-31 00:06:47
(9 hours ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-30 23:18:33
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.203.30.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 19:18:26.776919 2026] [security2:error] [pid 20793:tid 20793] [client 159.203.30.197:59206] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apS6Qs9JsmMnJBOFKHfsEQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-08-30 23:10:40
(10 hours ago)
URL scan
Brute-Force
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-30 23:09:01
(10 hours ago)
Wordpress hacking attempt
Web App Attack