๐บ๐ธ
TPI-Abuse
2026-09-17 12:43:53
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:43:49.384947 2026] [security2:error] [pid 19798:tid 19910] [client 159.223.51.245:63987] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.plumeraproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.plumeraproductions.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqvghdYvbzONyL5caX4EQgAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-17 12:39:31
(5 hours ago)
CrowdSec at atlas Reports Abuse
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-17 12:33:17
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-17 11:05:15
(6 hours ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=20
Hacking
๐ญ๐ท
bubausluge
2026-09-17 11:02:15
(6 hours ago)
Blocked by https://aegis.hr โ WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-09-17 ...
show more
Blocked by https://aegis.hr โ WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-09-17 10:43:43 to 2026-09-17 10:43:43
show less
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-09-17 10:05:09
(7 hours ago)
Abuse Detected (15)
Brute-Force
Web App Attack
Anonymous
2026-09-17 09:28:32
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 09:12:08
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:12:03.402618 2026] [security2:error] [pid 28619:tid 28619] [client 159.223.51.245:57586] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doctorbalog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doctorbalog.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aquu4wdeUfvRcFisO_JrrwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-17 08:55:25
(9 hours ago)
(wordpress) Apache: Failed WordPress login from 159.223.51.245 (SG/Singapore/-): 10 in the last 3600 ...
show more
(wordpress) Apache: Failed WordPress login from 159.223.51.245 (SG/Singapore/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 08:52:44
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:52:39.436788 2026] [security2:error] [pid 27117:tid 27117] [client 159.223.51.245:65120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sirio-b.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sirio-b.com"] [uri "/main/wp-json/wp/v2/users/"] [unique_id "aquqV2XQBejjO4Vg0hAhtQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:37:16
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:37:08.735545 2026] [security2:error] [pid 23822:tid 23822] [client 159.223.51.245:53709] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jdeloa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jdeloa.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aquKlBhFVHRf_naPKrQKbQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-17 06:20:09
(11 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:19:52
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.223.51.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:19:45.695811 2026] [security2:error] [pid 8057:tid 8057] [client 159.223.51.245:59416] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ubuciko.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ubuciko.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aquGgVdZdxJSrvEcG-eM-wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-17 05:59:32
(11 hours ago)
159.223.51.245 - - [17/Sep/2026:07:59:25 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 ...
show more
159.223.51.245 - - [17/Sep/2026:07:59:25 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
159.223.51.245 - - [17/Sep/2026:07:59:26 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
159.223.51.245 - - [17/Sep/2026:07:59:26 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
159.223.51.245 - - [17/Sep/2026:07:59:27 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
159.223.51.245 - - [17/Sep/2026:07:59:23 +0200] "GET / HTTP/1.1" 301 572 "-" "Mozilla/5.0
show less
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-17 05:55:03
(12 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack