πΊπΈ
TPI-Abuse
2026-09-19 22:13:33
(10 minutes ago)
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 18:13:29.693236 2026] [security2:error] [pid 481:tid 550] [client 168.144.246.246:63785] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eliteproductions.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eliteproductions.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8JCcjYOtwifBW_XtjJNQAAAQA"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 21:07:46
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 17:07:43.875412 2026] [security2:error] [pid 14482:tid 14482] [client 168.144.246.246:61527] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.northfortworthalliance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.northfortworthalliance.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq75n87II92GUg2UFsltVgAAAAY"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 19:02:09
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:02:04.011985 2026] [security2:error] [pid 32333:tid 32333] [client 168.144.246.246:57681] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fitnessgearmagazine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fitnessgearmagazine.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7cLKAEVtW2jUhin8MaHwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 17:37:32
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:37:27.715337 2026] [security2:error] [pid 15784:tid 15784] [client 168.144.246.246:55429] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.indiahouseportland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.indiahouseportland.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7IV402IIlCtmYjY5p-NwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
akasolutions.de
2026-09-19 16:56:46
(5 hours ago)
(wordpress) Failed wordpress login from 168.144.246.246 (SG/Singapore/-)
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-19 15:44:18
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 11:44:13.263267 2026] [security2:error] [pid 16610:tid 16610] [client 168.144.246.246:55482] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doublenaughtspycar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doublenaughtspycar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6tzeONnOLrsSJOIuPaFwAAAAs"], referer: https://t.co/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 15:21:26
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 11:21:22.301000 2026] [security2:error] [pid 26528:tid 26528] [client 168.144.246.246:63412] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.johncyphers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6ockq6sTgvO82DMuCBgQAAAAg"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 14:41:24
(7 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-19 13:55:04
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-login.php?redirect_to=https%3A%2F%2Ffrontaalpodium.c ...
show more
Bot / scanning and/or hacking attempts: GET /wp-login.php?redirect_to=https%3A%2F%2Ffrontaalpodium.com%, GET /wp-admin/index.php HTTP/1.1, POST /wp-login.php HTTP/1.1
show less
Hacking
Web App Attack
πͺπΈ
ofm-abuse
2026-09-19 13:14:39
(9 hours ago)
Brute-force
...
Brute-Force
Web App Attack
Bad Web Bot
π³π±
Alt255
2026-09-19 11:55:16
(10 hours ago)
[ti-22al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[ti-22al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 168.144.246.246 - - [19/Sep/2026:13:54:27 +0200] "POST /wp-login.php HTTP/1.1" 503 20135 "https://www.o4home.nl/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0"
168.144.246.246 - - [19/Sep/2026:13:54:39 +0200] "POST /wp-login.php HTTP/1.1" 503 24357 "https://www.o4home.nl/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
168.144.246.246 - - [19/Sep/2026:13:54:49 +0200] "POST /wp-login.php HTTP/1.1" 503 24357 "https://www.o4home.nl/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0"
168.144.246.246 - - [19/Sep/2026:13:54:57 +0200] "POST /wp-login.php HTTP/1.1" 503 24357 "https:
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 10:54:43
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.246.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:54:38.130180 2026] [security2:error] [pid 5125:tid 5125] [client 168.144.246.246:65474] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||deanfountain.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "deanfountain.com"] [uri "/blog/wp-json/wp/v2/users"] [unique_id "aq5p7mPQjeVsI05C3kYvqwAAAAQ"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 07:45:11
(14 hours ago)
Web attack blocked by Wordfence on www.gerhuntjens.nl (82 hits). Reported by CRMON.
Web App Attack