๐บ๐ธ
TPI-Abuse
2026-04-29 22:32:19
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 18:32:14.275907 2026] [security2:error] [pid 3550:tid 3550] [client 193.203.8.148:17141] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cpking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cpking.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afKG7tpsRVWYOEEndae27AAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 07:55:55
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 03:55:51.812723 2026] [security2:error] [pid 7300:tid 7300] [client 193.203.8.148:38635] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||donnysimonton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "donnysimonton.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afBoB_XhQG02fFna5YHCogAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 05:49:39
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 01:49:32.243705 2026] [security2:error] [pid 22972:tid 22972] [client 193.203.8.148:46343] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dynarol.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dynarol.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae2nbAkgUVck--UN-8n8qQAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-04-15 03:43:53
(2 months ago)
193.203.8.148 - - [14/Apr/2026:22:43:43 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2719 "-" "Apache-Http ...
show more
193.203.8.148 - - [14/Apr/2026:22:43:43 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2719 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
193.203.8.148 - - [14/Apr/2026:22:43:43 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2793 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
193.203.8.148 - - [14/Apr/2026:22:43:44 -0500] "GET /wp-login.php HTTP/1.1" 200 4494 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
193.203.8.148 - - [14/Apr/2026:22:43:52 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2718 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
193.203.8.148 - - [14/Apr/2026:22:43:53 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2794 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 00:23:56
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 20:23:48.488435 2026] [security2:error] [pid 3615:tid 3615] [client 193.203.8.148:32047] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sparler.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sparler.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adBaFNB1uBxKuTCmypsVlwAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 16:42:32
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 12:42:24.867629 2026] [security2:error] [pid 19332:tid 19332] [client 193.203.8.148:61169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ccoxes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ccoxes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac_t8BC1upRAcieQiVUXWQAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 11:52:00
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.203.8.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 07:51:57.820777 2026] [security2:error] [pid 1503:tid 1503] [client 193.203.8.148:20269] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leadek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leadek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac-p3WVvS8Y4-7oAOpOXcgAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-21 22:39:36
(7 months ago)
Forum/form spam
Web Spam
๐จ๐ฟ
lp
2025-11-09 13:22:18
(7 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-11-09T13:04:55+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-11-09T13:04:55+01:00 vpn Access-Reject 'cisco' station: 193.203.8.148 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-11-08 14:50:51
(7 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-11-08T14:54:24+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-11-08T14:54:24+01:00 vpn Access-Reject 'pc1' station: 193.203.8.148 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-11-07 20:51:38
(7 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-11-07T21:21:11+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-11-07T21:21:11+01:00 vpn Access-Reject 'cisco' station: 193.203.8.148 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-10-30 20:52:12
(7 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-10-30T20:46:54+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-10-30T20:46:54+01:00 vpn Access-Reject 'nigeriaoo' station: 193.203.8.148 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-10-30 14:51:12
(7 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-10-30T14:39:29+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-10-30T14:39:29+01:00 vpn Access-Reject 'cemerlang' station: 193.203.8.148 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-10-28 08:50:57
(8 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-10-28T09:44:08+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 193.203.8.148
2025-10-28T09:44:08+01:00 vpn Access-Reject 'sarge' station: 193.203.8.148 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ฎ๐ณ
dineshskt4all
2025-10-26 19:04:18
(8 months ago)
[Sun Oct 26 19:04:16.842292 2025] [proxy_fcgi:error] [pid 2209738:tid 139002321499840] [client 193.2 ...
show more
[Sun Oct 26 19:04:16.842292 2025] [proxy_fcgi:error] [pid 2209738:tid 139002321499840] [client 193.203.8.148:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force