๐บ๐ธ
TPI-Abuse
2026-09-20 20:37:04
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:36:59.772595 2026] [security2:error] [pid 22725:tid 22725] [client 195.15.238.249:45346] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lightbender.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lightbender.net"] [uri "/wp-json/wp/v2/users"] [unique_id "arBD62JB8MGY8VklPc4GZAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 11:00:24
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:00:19.897456 2026] [security2:error] [pid 1914:tid 1914] [client 195.15.238.249:60256] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||studioyau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "studioyau.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq-8wwHIRYaLsFlnH34uPgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 06:22:28
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
todix
2026-09-20 05:21:09
(2 days ago)
WebAttack or semilar from 195.15.238.249
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 04:50:39
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 00:50:33.439504 2026] [security2:error] [pid 28829:tid 28829] [client 195.15.238.249:34268] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bamedica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9mGZ043YG8LbUgMCX0PwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-09-20 00:46:13
(2 days ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐บ๐ธ
nyt
2026-09-19 17:17:41
(2 days ago)
WP User Enumeration, WP Author Enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:09:57
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:09:52.981815 2026] [security2:error] [pid 29566:tid 29566] [client 195.15.238.249:34880] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lemoulinavent.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lemoulinavent.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5tgNhW0i0kT1vwR-j_PgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-09-18 15:26:57
(3 days ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 195.15.238.249 (CH/Switzerland/Geneva/ ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 195.15.238.249 (CH/Switzerland/Geneva/Geneva/-)
show less
Brute-Force
๐ฉ๐ช
LRob
2026-09-18 09:17:10
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users (+1 more) | query: author=1 | 2026-09-18 09:17 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 15:14:20
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 11:14:13.634400 2026] [security2:error] [pid 2603:tid 2603] [client 195.15.238.249:56622] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||phalanxemail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "phalanxemail.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aqwDxZhNCtHaZM2RLZ8KdQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-17 14:05:17
(4 days ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-17 13:14:13
(4 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 11:16:13
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.15.238.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:16:10.247128 2026] [security2:error] [pid 10050:tid 10050] [client 195.15.238.249:40414] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thereisaplaceonearth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thereisaplaceonearth.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqvL-iIqTFc-P3lHp_MexgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-17 10:45:59
(4 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking