๐บ๐ธ
TPI-Abuse
2026-09-20 04:18:11
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 00:18:04.482258 2026] [security2:error] [pid 30762:tid 30762] [client 204.44.192.80:33848] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.souldata.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.souldata.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9efOj5d-x6orkwhgviswAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-20 03:47:36
(18 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฉ๐ช
maxpower
2026-09-19 23:59:15
(22 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 204.44.192.80 (US/United States/s163.servernam ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 204.44.192.80 (US/United States/s163.servername.online): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 204.44.192.80 - - [20/Sep/2026:01:59:11 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12063 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:42.0) Gecko/20100101 Firefox/42.0" "-" host=phedra.eu
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 21:54:34
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 17:54:28.782682 2026] [security2:error] [pid 555:tid 555] [client 204.44.192.80:41110] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||magnoliahillproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "magnoliahillproductions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8ElNJPCHw2TbK3qJB28QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2026-09-19 20:39:10
(1 day ago)
COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487). Operato ...
show more
COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. (225170-169)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 19:36:18
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:36:12.542216 2026] [security2:error] [pid 9685:tid 9685] [client 204.44.192.80:42546] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||futuresgrowhere.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "futuresgrowhere.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7kLLPTCVIQeZs98ZYlhgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 16:29:15
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 12:29:09.175857 2026] [security2:error] [pid 26767:tid 26767] [client 204.44.192.80:33928] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wholesalelivelobsters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wholesalelivelobsters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq64VeX-RlJ_5My6FIk4PQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 14:31:23
(1 day ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐ซ๐ท
masterguru
2026-09-19 13:39:06
(1 day ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 10:55:53
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:55:46.966226 2026] [security2:error] [pid 8539:tid 8539] [client 204.44.192.80:57342] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.arsenaultartistmanagement.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.arsenaultartistmanagement.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5qMrZLMJ1ydid8OW9gUAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-18 17:01:03
(2 days ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
cwytech
2026-09-18 06:58:03
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-wordpress_user-enum.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:53:07
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:53:03.646813 2026] [security2:error] [pid 12038:tid 12068] [client 204.44.192.80:58756] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||worldecom.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "worldecom.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqvir5kDq2DhVvQU9eYpSwAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 10:55:11
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 204.44.192.80 (s163.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:55:07.370152 2026] [security2:error] [pid 8687:tid 8701] [client 204.44.192.80:57914] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.gilesrentalcars.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.gilesrentalcars.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqvHC5bPj7kzHhM6z_MHOgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-17 08:05:17
(3 days ago)
Abuse Detected (9)
Brute-Force
Web App Attack