๐บ๐ธ
TPI-Abuse
2026-09-20 23:01:23
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:01:17.999978 2026] [security2:error] [pid 13685:tid 13781] [client 192.249.127.92:47174] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||strengthsmatter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "strengthsmatter.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arBlvfGrQhEEy9JUx5OKDwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-20 17:02:11
(2 days ago)
Bad_requests
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-20 06:48:16
(2 days ago)
192.249.127.92 - - [20/Sep/2026:06:47:48 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 ...
show more
192.249.127.92 - - [20/Sep/2026:06:47:48 +0000] "GET /?author=2 HTTP/1.1" 403 1170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0" "-" edge="192.249.127.92"
192.249.127.92 - - [20/Sep/2026:06:47:49 +0000] "GET /?author=3 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0" "-" edge="192.249.127.92"
192.249.127.92 - - [20/Sep/2026:06:47:50 +0000] "GET /?author=4 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0" "-" edge="192.249.127.92"
192.249.127.92 - - [20/Sep/2026:06:47:52 +0000] "GET /?author=5 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:43.0) Gecko/20100101 Firefox/43.0" "-" edge="192.249.127.92"
192.249.127.92 - - [20/Sep/2026:06:47:53 +0000] "GET /?author=6 HTTP/1.1" 403 1171 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:50.0) Gecko/20100101 Firefox/50.0" "-" edge="192.249.127.92"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 05:01:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 01:01:41.437139 2026] [security2:error] [pid 22422:tid 22422] [client 192.249.127.92:47448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kobraagencies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kobraagencies.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9otc-Xss1o-Ajpwg23mAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-20 04:13:58
(2 days ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 01:29:27
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:29:22.527170 2026] [security2:error] [pid 32331:tid 32331] [client 192.249.127.92:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rodrigoaldecoa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq828rBdgxRxuVq2BIK5jgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 22:26:49
(3 days ago)
2026-09-20T00:26:40.754967+02:00 wordpress(www.katrinzeidler.com)[2653454]: Blocked user enumeratio ...
show more
2026-09-20T00:26:40.754967+02:00 wordpress(www.katrinzeidler.com)[2653454]: Blocked user enumeration attempt from 192.249.127.92
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 21:51:56
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 17:51:53.576659 2026] [security2:error] [pid 21351:tid 21351] [client 192.249.127.92:41606] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bostonmarathonstories.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bostonmarathonstories.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8D-UdIH5ZxMetld7hxEwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 14:28:57
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 10:28:52.750359 2026] [security2:error] [pid 30039:tid 30039] [client 192.249.127.92:37448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||designingdestinynow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "designingdestinynow.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6cJCRaV4k6yNVKRUY9jAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-19 12:05:11
(3 days ago)
Too many Status 40X (14)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:08:35
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:08:28.369105 2026] [security2:error] [pid 30092:tid 30150] [client 192.249.127.92:36494] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chelseyrae.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chelseyrae.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5tLGkBbAuxpjlMh86SawAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-19 10:49:33
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐ช๐ธ
robotstxt
2026-09-19 10:47:28
(3 days ago)
192.249.127.92 - - [19/Sep/2026:10:46:28 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 ...
show more
192.249.127.92 - - [19/Sep/2026:10:46:28 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0" "-" edge="192.249.127.92"
192.249.127.92 - - [19/Sep/2026:10:46:29 +0000] "GET /?author=3 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:59.0) Gecko/20100101 Firefox/59.0" "-" edge="192.249.127.92"
192.249.127.92 - - [19/Sep/2026:10:46:30 +0000] "GET /?author=4 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0" "-" edge="192.249.127.92"
192.249.127.92 - - [19/Sep/2026:10:46:31 +0000] "GET /?author=5 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0" "-" edge="192.249.127.92"
192.249.127.92 - - [19/Sep/2026:10:46:32 +0000] "GET /?author=6 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" edge="192.249.127.92"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:46:34
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.249.127.92 (vps70277.inmotionhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:46:28.812356 2026] [security2:error] [pid 1451:tid 1451] [client 192.249.127.92:49324] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puckerbottombikinis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puckerbottombikinis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5oBP-H9-5YKCkrsjp8qgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-19 10:35:04
(3 days ago)
192.249.127.92 - - [19/Sep/2026:12:34:38 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 404 4962 "-" "Mo ...
show more
192.249.127.92 - - [19/Sep/2026:12:34:38 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 404 4962 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0"
192.249.127.92 - - [19/Sep/2026:12:34:40 +0200] "GET /?author=1 HTTP/1.1" 301 4587 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0"
192.249.127.92 - - [19/Sep/2026:12:34:40 +0200] "GET / HTTP/1.1" 200 7836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0"
192.249.127.92 - - [19/Sep/2026:12:34:42 +0200] "GET /?author=2 HTTP/1.1" 301 4588 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
192.249.127.92 - - [19/Sep/2026:12:34:44 +0200] "GET / HTTP/1.1" 200 7836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
192.249.127.92 - - [19/Sep/2026:12:34:45 +0200] "GET /?author=3 HTTP/1.1" 301 4589 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0"
show less
Web App Attack
Hacking