๐บ๐ธ
bigwavedave
2026-09-25 19:34:30
(9 hours ago)
Wordpress Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 15:05:05
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 11:04:59.695298 2026] [security2:error] [pid 8940:tid 8940] [client 168.144.177.229:54761] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||creationorevolution.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "creationorevolution.net"] [uri "/wp-json/wp/v2/users"] [unique_id "araNm0MW7dHOfW0MVYL8FwAAAAI"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 14:40:09
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 10:40:05.671219 2026] [security2:error] [pid 31938:tid 31938] [client 168.144.177.229:55883] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.budgetbyron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.budgetbyron.com"] [uri "/wp-json/wp/v2/users"] [unique_id "araHxYlNKS382oFY_HmqZgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 11:52:05
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 07:52:01.809066 2026] [security2:error] [pid 18182:tid 18293] [client 168.144.177.229:60589] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||trulyoriginalpurpleoctopus.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "trulyoriginalpurpleoctopus.art"] [uri "/wp-json/wp/v2/users"] [unique_id "arZgYXJ3e56W8ZU4mI6r1gAAABE"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 00:58:48
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 20:58:43.670676 2026] [security2:error] [pid 15815:tid 15815] [client 168.144.177.229:65108] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.plazahacienda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.plazahacienda.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arXHQyR9oG6Gna2xHhleWwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-24 23:23:22
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2026-09-24 17:02:35
(1 day ago)
168.144.177.229 - - [24/Sep/2026:19:02:02 +0200] "GET /wp-login.php HTTP/1.1" 200 8261 "https://duck ...
show more
168.144.177.229 - - [24/Sep/2026:19:02:02 +0200] "GET /wp-login.php HTTP/1.1" 200 8261 "https://duckduckgo.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0" 168.144.177.229 - - [24/Sep/2026:19:02:22 +0200] "POST /wp-login.php HTTP/1.1" 403 12621 "https://kurse.tortenatelier-schwanbeck.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15" 168.144.177.229 - - [24/Sep/2026:19:02:26 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fkurse.tortenatelier-schwanbeck.de%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 6471 "https://kurse.tortenatelier-schwanbeck.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" 168.144.177.229 - - [24/Sep/2026:19:02:28 +0200] "POST /wp-login.php HTTP/1.1" 403 12618 "https://kurse.tortenatelier-schwanbeck.de/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36
show less
Brute-Force
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-24 16:02:31
(1 day ago)
{"ClientAddr":"168.144.177.229:60521","ClientHost":"168.144.177.229","ClientPort":"60521","ClientUse ...
show more
{"ClientAddr":"168.144.177.229:60521","ClientHost":"168.144.177.229","ClientPort":"60521","ClientUsername":"-","DownstreamContentSize":17835,"DownstreamStatus":403,"Duration":200824513,"OriginContentSize":17835,"OriginDuration":196537056,"OriginStatus":403,"Overhead":4287457,"RequestAddr":"www.cleveradmin.de","RequestContentSize":133,"RequestCount":380443,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/wp-login.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-09-24T18:02:26.25642754+02:00","StartUTC":"2026-09-24T16:02:26.25642754Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-09-24T18:02:26+02:00"}
{"ClientAddr":"168.144.177.229:60521","ClientHost":"168.144.177.229","Clie
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 15:06:24
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 11:06:20.833934 2026] [security2:error] [pid 27876:tid 27876] [client 168.144.177.229:65173] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.theamarals.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arU8bJ6x6pPQVM3LFtyf_gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 12:06:15
(1 day ago)
[ti-27al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[ti-27al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 168.144.177.229 - - [24/Sep/2026:14:06:04 +0200] "POST /wp-login.php HTTP/1.1" 200 4408 "https://www.creativeaction.nl/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
168.144.177.229 - - [24/Sep/2026:14:06:06 +0200] "POST /wp-login.php HTTP/1.1" 200 4405 "https://www.creativeaction.nl/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
168.144.177.229 - - [24/Sep/2026:14:06:07 +0200] "POST /wp-login.php HTTP/1.1" 200 4405 "https://www.creativeaction.nl/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
creat
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-24 11:27:00
(1 day ago)
2026-09-24 13:23:23 WordPress login error from 168.144.177.229: invalid_username && 2026-09-24 13:23 ...
show more
2026-09-24 13:23:23 WordPress login error from 168.144.177.229: invalid_username && 2026-09-24 13:23:38 WordPress login error from 168.144.177.229: invalid_username && 2026-09-24 13:23:52 WordPress login error from 168.144.177.229: invalid_username && 27 more within 20 minutes
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 11:15:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:15:04.251825 2026] [security2:error] [pid 1454:tid 1454] [client 168.144.177.229:57267] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barecreationsaz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barecreationsaz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arUGOMId3JxBfwodIAkH0QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:12:52
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:12:49.485941 2026] [security2:error] [pid 7818:tid 7844] [client 168.144.177.229:50649] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.quantumgaze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.quantumgaze.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arSxUTr8hNF1CuPd_CPwlQAAABg"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:43:30
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.177.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:43:27.060324 2026] [security2:error] [pid 16386:tid 16386] [client 168.144.177.229:61752] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vividlee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vividlee.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "arSqb3aRgDK27eQ_mPc_QAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-09-24 02:02:10
(2 days ago)
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, ...
show more
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, injected payloads, or the signature of a vulnerability scanner. This is an attack on the sites we host, blocked on sight. Please check the machine behind it for an attack tool or malware. | method: GET | path: / | query: author=1 | 2026-09-24 02:02 UTC
show less
Hacking
Web App Attack