๐บ๐ธ
TPI-Abuse
2026-06-06 04:06:58
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 00:06:52.738050 2026] [security2:error] [pid 17100:tid 17100] [client 185.201.139.227:20091] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mbnetworking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mbnetworking.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiOc3PYDIr1GgEitu_E3pgAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-06-01 23:15:27
(1 week ago)
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 13:00:56
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 09:00:52.192841 2026] [security2:error] [pid 7217:tid 7217] [client 185.201.139.227:9929] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pastorg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pastorg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahBThLr34xezf1dpNR3wMwAAACI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-03-29 00:08:42
(2 months ago)
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based) - โช๏ธ Excessive 30X Errors (Decay ...
show more
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 00:39:56
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 20:39:48.714717 2026] [security2:error] [pid 2660001:tid 2660001] [client 185.201.139.227:47919] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frootloops.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frootloops.net"] [uri "/wp-json/wp/v2/users"] [unique_id "acCL1HnGhbfhkqFN5UIkXQAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-17 02:45:27
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 22:45:23.942005 2026] [security2:error] [pid 3462:tid 3462] [client 185.201.139.227:62743] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||donnysimonton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "donnysimonton.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abjAQ3Ew0KFSiw-WLHlW2QAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-03-16 08:18:09
(2 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-14 18:22:28
(3 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐จ๐ญ
backslash
2026-03-14 11:51:00
(3 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-04 13:15:51
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.139.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 08:15:47.485094 2026] [security2:error] [pid 21252:tid 21252] [client 185.201.139.227:52793] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pc-rack.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pc-rack.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aagwg08Gr9ZzLVxWyODpRgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-03-02 15:37:59
(3 months ago)
185.201.139.227 - - [02/Mar/2026:08:37:58 -0700] "POST /wp-login.php HTTP/1.1" 200 2334 "https://doo ...
show more
185.201.139.227 - - [02/Mar/2026:08:37:58 -0700] "POST /wp-login.php HTTP/1.1" 200 2334 "https://dooce.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force