๐บ๐ธ
TPI-Abuse
2025-11-16 18:14:42
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 13:14:34.782152 2025] [security2:error] [pid 28385:tid 28385] [client 188.166.250.91:49653] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tgaguide.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tgaguide.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRoUiqI8GvnJv7up7NJmMQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
zwebvigil
2025-11-16 17:58:21
(9 months ago)
188.166.250.91 [16/Nov/2025:09:58:19 -0800] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 196 "- ...
show more
188.166.250.91 [16/Nov/2025:09:58:19 -0800] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 196 "-" port=61982 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" "-" "-" "pershopai.com" 220
188.166.250.91 [16/Nov/2025:09:58:19 -0800] "GET //xmlrpc.php?rsd HTTP/1.1" 404 196 "-" port=61982 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" "-" "-" "pershopai.com" 420
188.166.250.91 [16/Nov/2025:09:58:20 -0800] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196 "-" port=61982 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" "-" "-" "pershopai.com" 241
188.166.250.91 [16/Nov/2025:09:58:20 -0800] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 196 "-" port=61982 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987
show less
Web App Attack
๐น๐ท
rtbh.com.tr
2025-11-15 20:09:56
(9 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฎ๐ฉ
Burayot
2025-11-15 07:07:58
(9 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 188.166.250.91 (SG/Singapore/-): 2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 188.166.250.91 (SG/Singapore/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 06:12:47
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 01:12:41.378161 2025] [security2:error] [pid 14102:tid 14102] [client 188.166.250.91:64085] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.birdlovesfish.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.birdlovesfish.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRgZ2c3og79w3GJG9KUCHgAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2025-11-15 06:09:39
(9 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-11-14 06:00:08
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 00:59:58.257085 2025] [security2:error] [pid 5997:tid 5997] [client 188.166.250.91:50271] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||emsystemsltd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "emsystemsltd.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRbFXgb6Gin-9s1HNNSs4AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
waltn3mtj
2025-11-13 23:02:00
(9 months ago)
Multiple probes and attempting to alter WP core files and posts. Also brute force XMLRPC attempts.
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2025-11-13 19:20:58
(9 months ago)
wp-includes scan
Web App Attack
๐ง๐ช
cmbplf
2025-11-13 17:26:19
(9 months ago)
3.318 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
WizardsToolkit
2025-11-12 08:38:22
(10 months ago)
attempted to access /wp-includes/wlwmanifest.xml
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 04:47:12
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 23:47:05.265164 2025] [security2:error] [pid 31688:tid 31688] [client 188.166.250.91:63264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artizandecor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artizandecor.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRQRSas1LnUpUWxwhYUjagAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2025-11-12 03:36:25
(10 months ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐บ๐ธ
TPI-Abuse
2025-11-08 07:16:21
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 02:16:14.300598 2025] [security2:error] [pid 2674:tid 2674] [client 188.166.250.91:63406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jgraue.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jgraue.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQ7uPhU71LRFbF3Lsy8nAAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 06:20:28
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.166.250.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 01:20:25.024279 2025] [security2:error] [pid 18227:tid 18227] [client 188.166.250.91:64641] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.eduempowermentsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.eduempowermentsolutions.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQ7hKWftCGvthmrCNX7EFQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack