πΊπΈ
TPI-Abuse
2026-07-30 00:19:56
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 20:19:52.058902 2026] [security2:error] [pid 4140575:tid 4140575] [client 166.1.131.74:16033] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||al-bukhari.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "al-bukhari.org"] [uri "/wp-json/wp/v2/users"] [unique_id "amqYqKffti504HpH-DhAogAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 20:25:24
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 16:25:17.772214 2026] [security2:error] [pid 1547784:tid 1547784] [client 166.1.131.74:30639] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||foxmm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "foxmm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amkQLYjtwu1DWHVdKNWOsAAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-07-28 18:37:51
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-26 23:06:10
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 19:06:04.899572 2026] [security2:error] [pid 2788:tid 2788] [client 166.1.131.74:45651] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cypro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cypro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amaS3IeBW-CPBexYCEfCGAAAABY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
DRI
2026-07-25 19:17:57
(1 week ago)
Web attack/Malicious activity detected
Web App Attack
π²πΎ
Rizzy
2026-07-16 22:18:31
(2 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π¨π
backslash
2026-07-14 00:39:08
(2 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
πΊπΈ
ambor
2026-05-22 01:09:52
(2 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-21 20:40:15
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 16:40:07.389948 2026] [security2:error] [pid 26772:tid 26879] [client 166.1.131.74:29811] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||danandlila.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "danandlila.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag9tp2DqYRqZ83xYsAFwFgAAAgM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-20 14:55:16
(2 months ago)
FPROCO WEBEXPLOIT 166.1.131.74 (166.1.131.74)
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-17 23:45:32
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 19:45:28.062784 2026] [security2:error] [pid 28894:tid 28894] [client 166.1.131.74:17377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pianosmith.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pianosmith.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agpTGDsHCSMk7Q1BNcy0WgAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-11 09:43:34
(2 months ago)
Web App Attack
Brute-Force
Web App Attack
π¦πΊ
MAGIC
2026-04-21 01:22:46
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-04-17 00:19:06
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 166.1.131.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 20:18:59.981378 2026] [security2:error] [pid 1728350:tid 1728350] [client 166.1.131.74:58113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodpage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodpage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeF8c5Xiwg_9bzCpeH2zEwAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-03-19 08:44:57
(4 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking