πΊπΈ
TPI-Abuse
2026-06-23 16:37:34
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 12:37:27.778379 2026] [security2:error] [pid 6864:tid 6864] [client 185.104.44.136:11154] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iplantotravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iplantotravel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajq2R6iK5D6TKexTUAshpAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 12:09:03
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 08:08:58.309817 2026] [security2:error] [pid 22693:tid 22693] [client 185.104.44.136:63080] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.batesstrategygroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.batesstrategygroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkl2hVZkS7oxXrKdKaSiQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 23:57:04
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 19:56:56.908687 2026] [security2:error] [pid 19032:tid 19032] [client 185.104.44.136:53238] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.realclean.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajh6SA81zV0Cwhltnv_q6gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 01:54:51
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 21:54:43.663130 2026] [security2:error] [pid 7304:tid 7304] [client 185.104.44.136:64162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.graymatterofdc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.graymatterofdc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdEY-KstvegSfZXUvamRwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 09:20:16
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 05:20:11.010082 2026] [security2:error] [pid 11406:tid 11432] [client 185.104.44.136:30390] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.chelseyrae.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.chelseyrae.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajZbS0Udeokx837lnusyAwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
R.G.
2026-06-19 04:51:11
(1 month ago)
(XMLRPCorWHATEVER) Get lost please 185.104.44.136 (UA/Ukraine/web964.default-host.net): 3 in the las ...
show more
(XMLRPCorWHATEVER) Get lost please 185.104.44.136 (UA/Ukraine/web964.default-host.net): 3 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-18 02:43:07
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 22:42:58.969192 2026] [security2:error] [pid 30055:tid 30055] [client 185.104.44.136:44654] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.67ronin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.67ronin.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajNbMobvSxAiEJRj7y2HVgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-17 18:29:56
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 14:29:51.791646 2026] [security2:error] [pid 31279:tid 31279] [client 185.104.44.136:20462] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.mrflatpeople.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.mrflatpeople.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajLnnxraqUo-P1MUFBQoHwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-17 17:59:40
(1 month ago)
Multiple WAF Violations
Web App Attack
π¨π¦
SSH-Admin
2026-06-14 09:00:05
(1 month ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
π¨π¦
SSH-Admin
2026-06-14 08:32:02
(1 month ago)
Probing for Exploits on ns74
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 03:52:06
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 23:51:59.249244 2026] [security2:error] [pid 873:tid 873] [client 185.104.44.136:24680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.disio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.disio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai4lXyxxbFIxCi5duvAc8wAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 00:17:59
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 20:17:50.915589 2026] [security2:error] [pid 31840:tid 31840] [client 185.104.44.136:52870] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vrevgaming.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vrevgaming.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aiyhrn_GtCl51RQmvSKlagAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 21:16:21
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 17:16:17.363461 2026] [security2:error] [pid 885:tid 885] [client 185.104.44.136:56788] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.teleplussolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.teleplussolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aix3IQ7S-5dXjaFjXIn3wAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 19:05:50
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.136 (web964.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 15:05:42.536495 2026] [security2:error] [pid 12176:tid 12176] [client 185.104.44.136:28502] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realdesigninterior.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realdesigninterior.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aisHBtZIdBx790ImQvCfagAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack