🇺🇸
nationaleventpros.com
2026-09-05 07:14:55
(21 hours ago)
WordPress login attempt
Brute-Force
🇺🇸
nationaleventpros.com
2026-09-03 06:08:23
(2 days ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-09-02 19:41:04
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 15:40:57.359875 2026] [security2:error] [pid 29158:tid 29158] [client 185.201.138.90:29559] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stormwlf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stormwlf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aph7yRfmUWClVpgNNddRLQAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-28 16:47:30
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-08-28 16:47 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-19 10:36:28
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 06:36:20.596366 2026] [security2:error] [pid 12165:tid 12165] [client 185.201.138.90:65195] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||asduk.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "asduk.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoWHJMNijajeaHyZ5vxHUAAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 21:48:01
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 17:47:54.845447 2026] [security2:error] [pid 17812:tid 17812] [client 185.201.138.90:56051] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||unitoolsupplies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "unitoolsupplies.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoTTCuQux0my_oSOmPQl7QAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-08-18 15:48:56
(2 weeks ago)
cloudlinux2 fail2ban: 2026-08-18 17:44:24,950 fail2ban.filter [1456]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-18 17:44:24,950 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 118.68.85.62 - 2026-08-18 17:44:24cloudlinux2 fail2ban: 2026-08-18 17:44:26,411 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 162.55.89.48 - 2026-08-18 17:44:25cloudlinux2 fail2ban: 2026-08-18 17:45:30,304 fail2ban.actions [1456]: NOTICE [plesk-modsecurity] Ban 118.68.85.62cloudlinux2 fail2ban: 2026-08-18 17:45:30,306 fail2ban.filter [1456]: INFO [recidive] Found 118.68.85.62 - 2026-08-18 17:45:30cloudlinux2 fail2ban: 2026-08-18 17:45:30,095 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 118.68.85.62 - 2026-08-18 17:45:30cloudlinux2 fail2ban: 2026-08-18 17:45:31,032 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 38.199.50.73 - 2026-08-18 17:45:31cloudlinux2 fail2ban: 2026-08-18 17:46:34,459 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 38.199.50.73 - 2026-08-18 17:46:34cloudlinux2 fail2ban: 2026-08-18 17:4
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 16:06:59
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 12:06:53.998588 2026] [security2:error] [pid 1489:tid 1489] [client 185.201.138.90:38687] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vonkugelgen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vonkugelgen.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoMxnUyKvQr18SMic-m1FgAAADI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-09 22:53:05
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 18:52:59.888508 2026] [security2:error] [pid 1672484:tid 1672484] [client 185.201.138.90:21813] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ankEy124ZK4SURwVkLpkPAAAAC0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-05 21:04:03
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 17:03:57.931629 2026] [security2:error] [pid 1865379:tid 1865379] [client 185.201.138.90:19053] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||innovacionesnimba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "innovacionesnimba.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anOlPQm1pxdeXs1IZjCmoQAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 15:41:07
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 11:41:02.673771 2026] [security2:error] [pid 1978119:tid 1978119] [client 185.201.138.90:33449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||steinmetzjewelers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "steinmetzjewelers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anIIDpzzepX2IGOMh5pcjwAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-02 23:24:38
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 19:24:33.257941 2026] [security2:error] [pid 3999480:tid 3999480] [client 185.201.138.90:14371] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wetlizarddiveteam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wetlizarddiveteam.com"] [uri "/wp-json/wp/v2/users"] [unique_id "am_RsRcLHSIwbVZ4jmoF_wAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-08-01 03:07:33
(1 month ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 19:18:50
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.138.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 15:18:46.640175 2026] [security2:error] [pid 2125249:tid 2125249] [client 185.201.138.90:36337] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mbnetworking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mbnetworking.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amevFuVF-_vsrAanCrsYrwAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-07-02 04:57:55
(2 months ago)
tilellit/wp-armour-ban
Hacking