๐บ๐ธ
ambor
2026-10-07 10:49:15
(3 minutes ago)
Honeypot triggered: /wp-json/wp/v2/users on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; ...
show more
Honeypot triggered: /wp-json/wp/v2/users on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36. Method: GET
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 08:27:59
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:27:54.860852 2026] [security2:error] [pid 12106:tid 12106] [client 182.253.126.71:32953] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rwabutazafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rwabutazafoundation.org"] [uri "/wp-json/wp/v2/users"] [unique_id "asYCikQfNksdIoBp82NVOgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 07:42:51
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 03:42:45.572304 2026] [security2:error] [pid 19584:tid 19584] [client 182.253.126.71:60134] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||n4fh.cosentient.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "n4fh.cosentient.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asX39T5yOW5km_N2ZYVaRgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 07:24:43
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 03:24:37.453306 2026] [security2:error] [pid 7222:tid 7222] [client 182.253.126.71:40661] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.funnyaaron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.funnyaaron.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asXzteVJiHCaP8YyTtjxbwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:43:31
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:43:24.759945 2026] [security2:error] [pid 21788:tid 21788] [client 182.253.126.71:38676] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jessicalevant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jessicalevant.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asXb_NVQAxbTiw1VDWv4GAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 21:56:37
(12 hours ago)
Web probing (2 hits in 24h) on 1valkenburg.nl,default-vhost: sensitive-path scans and/or 404 bursts. ...
show more
Web probing (2 hits in 24h) on 1valkenburg.nl,default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:18:18
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:18:11.462112 2026] [security2:error] [pid 6246:tid 6246] [client 182.253.126.71:12380] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||portlunchgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "portlunchgroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asVXg89kaB4wNcPN46LxegAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 20:09:55
(14 hours ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
CBJ
2026-10-06 16:05:26
(18 hours ago)
fail2ban: apache-random-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:25:46
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:25:42.398422 2026] [security2:error] [pid 1230:tid 1230] [client 182.253.126.71:38873] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prcomputersolutions.com.anthonyanimalclinic.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prcomputersolutions.com.anthonyanimalclinic.net"] [uri "/wp-json/wp/v2/users"] [unique_id "asUS9v_TpuAT_wLW7XXIPAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-06 13:50:02
(21 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐น๐ท
oalver
2026-10-06 11:55:11
(22 hours ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-admin/ (HTTP 302). First seen: 2026-10-06. Risk score: 30/100.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:34:57
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:34:54.731915 2026] [security2:error] [pid 27157:tid 27157] [client 182.253.126.71:9258] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||onlinesuretybonds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "onlinesuretybonds.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ar96vghXINcEyz-rI1MBmwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 08:50:44
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:50:39.730397 2026] [security2:error] [pid 8004:tid 8004] [client 182.253.126.71:48218] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tileoptima.mooseled.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tileoptima.mooseled.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ar9wX432kscaTh3AWFyrxAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:05:05
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 182.253.126.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:04:58.438076 2026] [security2:error] [pid 28660:tid 28660] [client 182.253.126.71:60022] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zeetec.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zeetec.nl"] [uri "/wp-json/wp/v2/users"] [unique_id "ar9XmmmMraZlRRg143bYRQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack