🇺🇸
TPI-Abuse
2026-09-11 03:34:23
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:34:19.616051 2026] [security2:error] [pid 1740819:tid 1740819] [client 188.189.92.229:58260] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arogun.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arogun.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqN2u3Gj6hQV0LBSnVaC7gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 15:32:02
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:31:57.342416 2026] [security2:error] [pid 1525:tid 1525] [client 188.189.92.229:59748] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marianozaro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marianozaro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqLNbT9Pw8JzldgGJn8SBgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 14:53:31
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 10:53:27.791964 2026] [security2:error] [pid 19647:tid 19647] [client 188.189.92.229:61220] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atmoorehealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atmoorehealthcare.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqLEZ5o6bk1B2zu-M_kkAQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-10 04:12:26
(1 day ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇲🇹
Malta
2026-09-10 02:29:53
(1 day ago)
188.189.92.229 - - [10/Sep/2026:04:29:52 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintos ...
show more
188.189.92.229 - - [10/Sep/2026:04:29:52 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇩🇪
FeG Deutschland
2026-09-10 01:59:35
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇫🇷
masterguru
2026-09-09 02:37:10
(2 days ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 188.189.92.229 (BE/Belgium/-): 1 in the last ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 188.189.92.229 (BE/Belgium/-): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-09 02:02:42
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:02:37.862866 2026] [security2:error] [pid 20367:tid 20367] [client 188.189.92.229:60328] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rachelfia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rachelfia.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC-PaN5l8HIg6OehYGhbQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:18:23
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:18:16.545885 2026] [security2:error] [pid 536297:tid 536361] [client 188.189.92.229:58496] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nicholsinvest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nicholsinvest.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCXuN9PZyRc2a7l9tqAlwAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-09-08 22:27:15
(2 days ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:33:06
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:32:58.991983 2026] [security2:error] [pid 14360:tid 14360] [client 188.189.92.229:60494] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bigheartskitchen.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bigheartskitchen.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAqqoAxOHF8XFJVPsjSpwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 14:59:29
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:43:17
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 188.189.92.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:43:12.606183 2026] [security2:error] [pid 24312:tid 24312] [client 188.189.92.229:60220] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.market1st.bridgital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.market1st.bridgital.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_KoOPHoHLnZXyq-70yPgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 04:21:36
(3 days ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-08 04:21 UTC
Brute-Force
Web App Attack
🇪🇸
masterguru
2026-09-07 11:02:16
(4 days ago)
*Port Scan* detected from 188.189.92.229 (BE/Belgium/-). 11 hits in the last 297 seconds (0-122)
Port Scan