๐บ๐ธ
TPI-Abuse
2026-08-23 14:12:17
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:12:10.694263 2026] [security2:error] [pid 1085:tid 1085] [client 2.29.5.107:16356] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||giveorcas.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "giveorcas.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aor_umXtf02zozOsYOciEwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 13:06:13
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:06:09.147261 2026] [security2:error] [pid 481:tid 481] [client 2.29.5.107:17078] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tourissue.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tourissue.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorwQb52HngGs4-NVv4OkAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:18:46
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:18:41.165041 2026] [security2:error] [pid 25674:tid 25674] [client 2.29.5.107:63504] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mjkhan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mjkhan.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorlIU19lH_WWq04-UG-AwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:55:33
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:55:27.792117 2026] [security2:error] [pid 27757:tid 27757] [client 2.29.5.107:32562] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fundingworkingcapital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fundingworkingcapital.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorfr1VnOS9-PRHPP8hpswAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:36:04
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:35:55.716011 2026] [security2:error] [pid 30901:tid 31060] [client 2.29.5.107:20032] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gilesrentalcars.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gilesrentalcars.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorbG1LeYd2xy1qTNFdG2wAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:00:36
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:00:32.698365 2026] [security2:error] [pid 6903:tid 6903] [client 2.29.5.107:42386] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lkabookeeping.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lkabookeeping.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorS0BsivlpRf4zMgm4EJQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-23 10:44:00
(4 days ago)
cloudlinux2 fail2ban: 2026-08-23 12:39:10,344 fail2ban.actions [1496]: NOTICE [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-23 12:39:10,344 fail2ban.actions [1496]: NOTICE [plesk-wordpress] Ban 172.98.32.221cloudlinux2 fail2ban: 2026-08-23 12:39:09,885 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 172.98.32.221 - 2026-08-23 12:39:09cloudlinux2 fail2ban: 2026-08-23 12:39:10,349 fail2ban.filter [1496]: INFO [recidive] Found 172.98.32.221 - 2026-08-23 12:39:10cloudlinux2 fail2ban: 2026-08-23 12:39:52,953 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 63.135.161.36 - 2026-08-23 12:39:52cloudlinux2 fail2ban: 2026-08-23 12:41:09,405 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 45.132.227.250 - 2026-08-23 12:41:08cloudlinux2 fail2ban: 2026-08-23 12:41:13,700 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 45.132.227.250 - 2026-08-23 12:41:13cloudlinux2 fail2ban: 2026-08-23 12:43:07,258 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 170.101.96.66 - 2026-08-23 12:43:07cloudlinux2 fail2ban: 2026-08-23 12:
show less
Web App Attack
๐ฉ๐ช
LRob
2026-08-23 09:48:24
(4 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-23 09:48 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 09:21:10
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:21:02.309951 2026] [security2:error] [pid 27548:tid 27548] [client 2.29.5.107:42536] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||riccardiagency.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "riccardiagency.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoq7frqIPjFuiQOzlWX1qgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-22 22:12:25
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 22:04:31
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 18:04:27.297004 2026] [security2:error] [pid 2874:tid 2874] [client 2.29.5.107:50736] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jacquelineperriam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jacquelineperriam.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aooc69wvvcJYaRnabgfTigAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 20:55:02
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:54:56.096658 2026] [security2:error] [pid 18736:tid 18736] [client 2.29.5.107:40200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||meganmurph.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "meganmurph.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aooMoPehU2zXFMyaOVvaRwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:35:20
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:35:14.589396 2026] [security2:error] [pid 20461:tid 20461] [client 2.29.5.107:57696] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marydeal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marydeal.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aond0lFTAZPYyAG-SvywrQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-22 17:11:20
(5 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 12:14:51
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.5.107 (static.107.5.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:14:46.762640 2026] [security2:error] [pid 21698:tid 21698] [client 2.29.5.107:38718] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rblep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rblep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomStnqtkOSE5H8gQdC0ygAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack