๐ซ๐ท
LoneRider
2026-09-28 01:07:24
(22 hours ago)
167.172.83.30 - - [28/Sep/2026:03:07:08 +0200] "POST /wp-login.php HTTP/1.1" 200 8644 "https://maksi ...
show more
167.172.83.30 - - [28/Sep/2026:03:07:08 +0200] "POST /wp-login.php HTTP/1.1" 200 8644 "https://maksiprint.com.mk/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
167.172.83.30 - - [28/Sep/2026:03:07:17 +0200] "POST /wp-login.php HTTP/1.1" 200 8642 "https://maksiprint.com.mk/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0"
167.172.83.30 - - [28/Sep/2026:03:07:22 +0200] "POST /wp-login.php HTTP/1.1" 200 8642 "https://maksiprint.com.mk/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:121.0) Gecko/20100101 Firefox/121.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 00:35:06
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 20:35:00.236583 2026] [security2:error] [pid 28079:tid 28079] [client 167.172.83.30:54146] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.btccasting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.btccasting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arm2NFyevBAyDZIKgkLAxgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 23:24:57
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 19:24:49.527329 2026] [security2:error] [pid 31901:tid 31916] [client 167.172.83.30:61998] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hooknpatch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hooknpatch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "armlwe6Jo384YtRVGI99RAAAAAM"], referer: https://duckduckgo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 22:58:52
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 18:58:45.416914 2026] [security2:error] [pid 24279:tid 24279] [client 167.172.83.30:59729] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drgtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drgtek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "armfpW8GkAOdcJAN_FdwdAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 21:39:52
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 17:39:49.716595 2026] [security2:error] [pid 19736:tid 19736] [client 167.172.83.30:56348] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ecruhairsalon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ecruhairsalon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "armNJfTCA16hhzQJHgbXAwAAAAU"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 21:09:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 17:09:03.066388 2026] [security2:error] [pid 27025:tid 27025] [client 167.172.83.30:62130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.staging.justicehoward.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.staging.justicehoward.com"] [uri "/wp-json/wp/v2/users"] [unique_id "armF7780AW75iLcT4DTsGgAAAAk"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 17:00:26
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 13:00:22.508432 2026] [security2:error] [pid 29520:tid 29520] [client 167.172.83.30:63448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ardeeapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ardeeapps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arlLpp_YEULrrj5YisKbHAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 17:13:57
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 13:13:52.358675 2026] [security2:error] [pid 2420:tid 2420] [client 167.172.83.30:54009] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.solucionesmercadeodigital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.solucionesmercadeodigital.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arf9UGqdU3U0EM8l5vsCJwAAAAk"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gigatech
2026-09-26 12:45:03
(2 days ago)
Webserver Probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 00:48:53
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 20:48:45.587930 2026] [security2:error] [pid 7717:tid 7717] [client 167.172.83.30:62536] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dd214chronicle.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dd214chronicle.org"] [uri "/wp-json/wp/v2/users"] [unique_id "arcWbdSL2w8oiYyCG8tVFwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-25 22:59:45
(3 days ago)
[ti-27al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[ti-27al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 167.172.83.30 - - [26/Sep/2026:00:49:27 +0200] "POST /wp-login.php HTTP/1.1" 301 6581 "https://www.denpinternational.nl/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
167.172.83.30 - - [26/Sep/2026:00:52:44 +0200] "POST /wp-login.php HTTP/1.1" 301 6581 "https://www.denpinternational.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
167.172.83.30 - - [26/Sep/2026:00:56:13 +0200] "POST /wp-login.php HTTP/1.1" 301 6581 "https://www.denpinternational.nl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:119.0) Gecko/20100101 Firefox/119.0"
denpadvieshuis.nl
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-25 16:33:52
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
cwytech
2026-09-25 16:22:05
(3 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 08:17:17
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.83.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 04:17:10.033026 2026] [security2:error] [pid 26188:tid 26188] [client 167.172.83.30:55679] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kaldaragroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kaldaragroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arYuBvqfNU6yslvrr978ZwAAAA8"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-23 16:02:32
(5 days ago)
(wordpress) Failed wordpress login from 167.172.83.30 (SG/Singapore/-): (CF_ENABLE)
Brute-Force