๐บ๐ธ
TPI-Abuse
2026-06-26 14:42:31
(21 seconds ago)
(mod_security) mod_security (id:225170) triggered by 196.202.182.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 196.202.182.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 10:42:25.409088 2026] [security2:error] [pid 13311:tid 13311] [client 196.202.182.214:59211] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||otraes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "otraes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aj6P0eZthNUjQjn51-Yu9gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-06-24 10:57:12
(2 days ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ธ๐ฌ
securejdprop
2026-06-22 10:18:08
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing. crowdsecurity/http-probing
Hacking
Web App Attack
๐ฉ๐ช
findlab
2026-06-22 07:30:01
(4 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 16:40:59
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 196.202.182.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 196.202.182.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 12:40:52.192757 2026] [security2:error] [pid 7008:tid 7008] [client 196.202.182.214:50817] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||egelfitness.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "egelfitness.nl"] [uri "/wp-json/wp/v2/users"] [unique_id "ajVxFCktn-Wgi0lgXdbGFAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 16:02:25
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 196.202.182.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 196.202.182.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 12:02:19.551638 2026] [security2:error] [pid 8239:tid 8239] [client 196.202.182.214:62626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||digi-estudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "digi-estudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajVoC6HHQS8MFcgcGMUmvwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-06-19 14:41:58
(1 week ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 196.202.182.214 (KE/Kenya/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 196.202.182.214 (KE/Kenya/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TAY
2026-06-19 08:54:25
(1 week ago)
196.202.182.214 - - [19/Jun/2026:16:53:19 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6328 "-" "Mozilla/5 ...
show more
196.202.182.214 - - [19/Jun/2026:16:53:19 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6328 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
196.202.182.214 - - [19/Jun/2026:16:53:54 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6328 "-" "Mozilla/5.0 (Windows NT 10.0; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.0.0 Safari/537.36"
196.202.182.214 - - [19/Jun/2026:16:54:25 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6328 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/89.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-18 13:29:43
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 196.202.182.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 196.202.182.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 09:29:38.661460 2026] [security2:error] [pid 2390:tid 2390] [client 196.202.182.214:61581] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rajabarber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rajabarber.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajPywhCOGI8C6S1_5YR75AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack