๐บ๐ธ
TPI-Abuse
2026-09-20 08:36:59
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 04:36:54.406863 2026] [security2:error] [pid 25884:tid 25884] [client 167.250.5.4:34894] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tomslawmd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tomslawmd.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq-bJnJDE1GajQqll-kcqQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:39:42
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:39:38.591815 2026] [security2:error] [pid 10969:tid 10969] [client 167.250.5.4:41964] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ggaccounting.services|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ggaccounting.services"] [uri "/wp-json/wp/v2/users"] [unique_id "aqkgauleFVkJfZIUQFC8RAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-02 17:07:35
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
Anonymous
2026-09-02 00:10:37
(3 weeks ago)
WordPress Brute Force
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-30 12:22:14
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:13:10
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:13:03.358047 2026] [security2:error] [pid 2754589:tid 2754676] [client 167.250.5.4:35182] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||noharm-nofowl.plumeraproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "noharm-nofowl.plumeraproductions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apGzjy1sB9VMuemgdcUwmwAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 02:57:46
(4 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-18 17:59:10
(1 month ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-12 00:10:37
(1 month ago)
abuse php function Attack
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-11 03:54:48
(1 month ago)
[server.tmg.gr] httpd-suspicious-path: sites=www.cardiorenal2023.gr; logs=/var/log/httpd/domains/car ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=www.cardiorenal2023.gr; logs=/var/log/httpd/domains/cardiorenal2023.gr.log; samples=/?author=3
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 01:50:08
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 21:50:04.074108 2026] [security2:error] [pid 3869337:tid 3869337] [client 167.250.5.4:40458] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.skintormint.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.skintormint.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "anp_zDTwSFx9HjstfJ-YNAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 00:41:34
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 20:41:29.921459 2026] [security2:error] [pid 3872459:tid 3872482] [client 167.250.5.4:52798] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nicholsinvest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nicholsinvest.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anpvuSgUvv96viJguk0o0QAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-08-11 00:00:16
(1 month ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 23:15:15
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 167.250.5.4 (nb4.servidoraweb.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 19:15:09.311362 2026] [security2:error] [pid 22140:tid 22140] [client 167.250.5.4:54134] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||saadeh.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "saadeh.ws"] [uri "/wp-json/wp/v2/users"] [unique_id "anpbfXEmmnXTYvgdRJMrVwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-10 23:06:15
(1 month ago)
6.025 requests to many distinct domains in 1 hour (2w6d9h)
Brute-Force
Bad Web Bot