๐ฉ๐ช
4server
2026-09-19 20:54:48
(12 hours ago)
[SatSep1922:54:42.8670092026][security2:error][pid1229645:tid1229685][client193.202.81.59:0]ModSecur ...
show more
[SatSep1922:54:42.8670092026][security2:error][pid1229645:tid1229685][client193.202.81.59:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"prstartup.ch\"][uri\"/xmlrpc.php\"][unique_id\"aq72kiS7QNC6EFZt2RNZaQAAAcE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-18 21:39:11
(1 day ago)
Brute-force login attack detected by WordPress firewall.
Brute-Force
๐ซ๐ท
Tilellit.PRO
2026-06-28 07:49:38
(2 months ago)
Fail2Ban banned 193.202.81.59 for security violations in jail wp-armour. Log: 2026/06/28 07:49:38 [e ...
show more
Fail2Ban banned 193.202.81.59 for security violations in jail wp-armour. Log: 2026/06/28 07:49:38 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 193.202.81.59 | Target: wplogin" , client: 193.202.81.59, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-05-21 16:40:28
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 12:40:20.566511 2026] [security2:error] [pid 27341:tid 27346] [client 193.202.81.59:11877] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||apada.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "apada.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag81dEk1WFxQEyOuIsLDHAAAAEE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 04:13:15
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 00:13:09.943693 2026] [security2:error] [pid 20160:tid 20160] [client 193.202.81.59:27383] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||koeckeritz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "koeckeritz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag6GVUyR-MWcHqBIXw9ulAAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-18 12:23:31
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 08:23:24.466252 2026] [security2:error] [pid 25286:tid 25286] [client 193.202.81.59:38169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alan-ip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alan-ip.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agsEvN7U0-pKFI0lv0jWBQAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 22:04:33
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 18:04:28.870195 2026] [security2:error] [pid 32237:tid 32237] [client 193.202.81.59:55691] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rookscpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rookscpa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agZG7G9p5BiAfTiw9aRBXwAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-12 01:03:57
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 21:03:55.220502 2026] [security2:error] [pid 3463481:tid 3463481] [client 193.202.81.59:41427] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||slimlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "slimlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adrvez6rQtXr9tOWYyYM-AAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-03-02 18:31:50
(6 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-23 00:00:55
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 19:00:42.157426 2026] [security2:error] [pid 2222:tid 2293] [client 193.202.81.59:54745] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||heworeblack.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "heworeblack.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXK6Kk3x5_D6fwv2P1q5XAAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 19:22:19
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 14:22:14.784644 2026] [security2:error] [pid 23889:tid 23889] [client 193.202.81.59:31995] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greatchristianadventure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greatchristianadventure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJ45qcNJ7KacRi2m2TKIQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 18:52:11
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:52:04.765261 2026] [security2:error] [pid 8341:tid 8341] [client 193.202.81.59:40455] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||celltechs.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "celltechs.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJx1LKXO9rsNbPzBGajzAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 18:12:15
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:12:11.680931 2026] [security2:error] [pid 23872:tid 23872] [client 193.202.81.59:32607] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jan-wilson.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jan-wilson.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJoe8YJlVljbDlmDwy7DQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-04 10:10:13
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 05:10:06.188430 2026] [security2:error] [pid 25975:tid 25975] [client 193.202.81.59:42075] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||saadeh.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "saadeh.ws"] [uri "/wp-json/wp/v2/users/"] [unique_id "aVo8fhwLdKJhyWg1gHN1IAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-03 00:03:20
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.81.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 19:03:17.374591 2026] [security2:error] [pid 22127:tid 22127] [client 193.202.81.59:49495] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aVhcxbhjb2nTZFXs0m7IiwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack