Anonymous
2026-06-06 04:20:10
(12 hours ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-06 03:22:42
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 23:22:33.863257 2026] [security2:error] [pid 2133:tid 2133] [client 185.5.208.196:33382] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.digi-estudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.digi-estudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiOSefCNhGKfbB0sTsnF-wAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 21:36:38
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 17:36:34.171213 2026] [security2:error] [pid 10971:tid 10971] [client 185.5.208.196:37582] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.breezentry.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.breezentry.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiNBYpv_OuH7G8OX8SYoowAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-06-04 10:35:23
(2 days ago)
185.5.208.196 - - [04/Jun/2026:05:35:21 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4307 "-" "Mozilla/5.0 ...
show more
185.5.208.196 - - [04/Jun/2026:05:35:21 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0"
185.5.208.196 - - [04/Jun/2026:05:35:22 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:86.0) Gecko/20100101 Firefox/86.0"
185.5.208.196 - - [04/Jun/2026:05:35:22 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4308 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:98.0) Gecko/20100101 Firefox/98.0"
185.5.208.196 - - [04/Jun/2026:05:35:22 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
185.5.208.196 - - [04/Jun/2026:05:35:23 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 06:05:44
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 02:05:39.162454 2026] [security2:error] [pid 18544:tid 18544] [client 185.5.208.196:43836] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||parastesh.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "parastesh.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aiEVs8TIoX2DANS6-T23YgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 01:24:22
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 21:24:15.211547 2026] [security2:error] [pid 32629:tid 32629] [client 185.5.208.196:52448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.texascottagebakers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.texascottagebakers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiDTv3wQxM4ErojO1e1abgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 13:37:11
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 09:37:07.936665 2026] [security2:error] [pid 15355:tid 15514] [client 185.5.208.196:57786] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vinylnotespodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vinylnotespodcast.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiAuA2hXiueB7FeUcENotgAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 23:06:48
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 19:06:40.152478 2026] [security2:error] [pid 26277:tid 26277] [client 185.5.208.196:56400] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgesmarina.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah9iAMwODRkSLcx9fDkvMAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 22:13:18
(3 days ago)
185.5.208.196 - - [03/Jun/2026:00:13:07 +0200] "POST /wp-login.php HTTP/1.1" 200 2988 "-" "Mozilla/5 ...
show more
185.5.208.196 - - [03/Jun/2026:00:13:07 +0200] "POST /wp-login.php HTTP/1.1" 200 2988 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0"
185.5.208.196 - - [03/Jun/2026:00:12:52 +0200] "POST /wp-login.php HTTP/1.1" 200 3495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0"
185.5.208.196 - - [03/Jun/2026:00:13:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0"
185.5.208.196 - - [03/Jun/2026:00:12:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0"
185.5.208.196 - - [03/Jun/2026:00:13:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-02 18:50:22
(3 days ago)
[redacted] 185.5.208.196 - - [02/Jun/2026:20:50:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 185.5.208.196 - - [02/Jun/2026:20:50:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:20:50:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:20:50:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:20:50:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:20:50:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:20:50:21 +0200]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 17:47:24
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:47:17.827938 2026] [security2:error] [pid 23346:tid 23346] [client 185.5.208.196:42660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tcomputerguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tcomputerguy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah8XJeRAUCVXzrRFbPhVdQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:16:19
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:16:12.225814 2026] [security2:error] [pid 26778:tid 26778] [client 185.5.208.196:47542] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.97films.media|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.97films.media"] [uri "/wp-json/wp/v2/users"] [unique_id "ah8BzMjVlyUVUG0WQAGk8AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 15:43:26
(4 days ago)
[redacted] 185.5.208.196 - - [02/Jun/2026:17:43:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 185.5.208.196 - - [02/Jun/2026:17:43:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:17:43:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:17:43:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:63.0) Gecko/20100101 Firefox/63.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:17:43:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:17:43:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0"
[redacted] 185.5.208.196 - - [02/Jun/2026:17:43:25 +0200]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:41:51
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:41:47.058541 2026] [security2:error] [pid 28218:tid 28218] [client 185.5.208.196:52096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kh6jim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kh6jim.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah7rq4rFe_h9X8SXt6s7EgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 12:58:59
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 185.5.208.196 (ateliermedia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 08:58:54.034974 2026] [security2:error] [pid 32625:tid 32675] [client 185.5.208.196:47818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.plumeraproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.plumeraproductions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah7TjjoDmTgk5-8DA4nBdAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack