๐บ๐ธ
TPI-Abuse
2026-05-13 03:13:14
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 167.71.136.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.71.136.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 23:13:09.191785 2026] [security2:error] [pid 16631:tid 16631] [client 167.71.136.93:41400] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||auto.fletcherdouglas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "auto.fletcherdouglas.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agPsRRl11V5Cl--mY4d8-QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-05-13 02:53:15
(3 weeks ago)
๐ Probes for tons of inexistent files and/or PHP scripts
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-05-13 01:58:49
(3 weeks ago)
15.021 requests in 1 hour (2mos2w5d)
Brute-Force
Bad Web Bot
๐บ๐ธ
wordpresshosting.solutions
2026-05-13 01:35:31
(3 weeks ago)
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 167.71.136.93 - - [13/May/2026: ...
show more
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 167.71.136.93 - - [13/May/2026:01:35:10 +0000] "GET /wp-json/wp/v2/users?include=0,1&_fields=id,slug,name HTTP/1.1" 401 4940 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
167.71.136.93 - - [13/May/2026:01:35:30 +0000] "GET /wp-json/wp/v2/users?per_page=50&page=1&_fields=slug HTTP/1.1" 401 4940 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-05-13 01:31:58
(3 weeks ago)
Probing websites for vulnerabilities
Web App Attack
๐ฉ๐ช
filstal.org
2026-05-13 01:29:25
(3 weeks ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths detected by Fail2Ban
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-05-13 01:25:37
(3 weeks ago)
2026-05-13T03:25:36.732803+02:00 zanati wp(sahpa.co.za)[1923874]: Blocked user enumeration attempt f ...
show more
2026-05-13T03:25:36.732803+02:00 zanati wp(sahpa.co.za)[1923874]: Blocked user enumeration attempt from 167.71.136.93
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 01:25:07
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 167.71.136.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.71.136.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 21:25:04.063294 2026] [security2:error] [pid 15375:tid 15375] [client 167.71.136.93:50394] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iconflgc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iconflgc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agPS8J2DRiyoDFzfSQBuSwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 01:08:30
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 167.71.136.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.71.136.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 21:08:22.878924 2026] [security2:error] [pid 14554:tid 14554] [client 167.71.136.93:39952] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hellomdinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hellomdinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agPPBuqcD9EBbI2GUYSPZQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-13 01:05:44
(3 weeks ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2026-05-13 00:45:07
(3 weeks ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
Anonymous
2026-05-13 00:38:41
(3 weeks ago)
2026-05-13T02:38:40.409406+02:00 aion wordpress[1937391]: Blocked user enumeration attempt from 167. ...
show more
2026-05-13T02:38:40.409406+02:00 aion wordpress[1937391]: Blocked user enumeration attempt from 167.71.136.93
...
show less
Hacking
Brute-Force
๐ฉ๐ช
Hazzard
2026-05-13 00:06:29
(3 weeks ago)
(wordpress) Failed wordpress login from 167.71.136.93 (GB/United Kingdom/England/Slough/-/[redacted] ...
show more
(wordpress) Failed wordpress login from 167.71.136.93 (GB/United Kingdom/England/Slough/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-12 23:37:14
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 167.71.136.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.71.136.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 19:37:10.160474 2026] [security2:error] [pid 4017:tid 4017] [client 167.71.136.93:55946] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.holistichealth4u2.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.holistichealth4u2.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agO5pnvbhaR3vf789eTQnwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-05-12 23:02:00
(3 weeks ago)
WordPress author enumeration
Web App Attack