๐บ๐ธ
TPI-Abuse
2026-06-14 19:48:32
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.87.216.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.87.216.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 15:48:26.521023 2026] [security2:error] [pid 4533:tid 4552] [client 212.87.216.161:65335] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ceresfund.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ceresfund.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai8Fivi_qRukjtbAYo2G1wAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 11:58:08
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 212.87.216.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.87.216.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 07:58:00.975835 2026] [security2:error] [pid 29498:tid 29498] [client 212.87.216.161:14207] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clinicacero.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clinicacero.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ailRSJCUy-aGMM0midLdNAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 17:25:34
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 212.87.216.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.87.216.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 13:25:26.119728 2026] [security2:error] [pid 23748:tid 23748] [client 212.87.216.161:59857] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aares2026.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aares2026.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aihMhp_ZwExc637ZnprQIQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 07:15:02
(2 weeks ago)
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-04-25 01:55:30
(1 month ago)
[redacted] 212.87.216.161 - - [25/Apr/2026:02:55:26 +0100] "GET /[redacted] HTTP/1.1" 302 1517 0/411 ...
show more
[redacted] 212.87.216.161 - - [25/Apr/2026:02:55:26 +0100] "GET /[redacted] HTTP/1.1" 302 1517 0/41153 "https://[redacted]" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" [redacted] 212.87.216.161 - - [25/Apr/2026:02:55:29 +0100] "GET /[redacted] HTTP/1.1" 302 1518 0/43437 "https://[redacted]" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-03-25 21:03:06
(2 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 212.87.216.161 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 212.87.216.161 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐ง๐ช
voormedia
2026-02-09 05:09:21
(4 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-07 20:00:09
(4 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-07 19:05:08
(4 months ago)
[WAZUH] Mixed case extension detected (case variation bypass)
Hacking
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-02-07 11:40:22
(4 months ago)
XML RPC Scan Activities
Brute-Force
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-02-06 07:17:47
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฎ๐ฉ
sockominfo
2026-02-05 23:00:31
(4 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-05 22:40:17
(4 months ago)
[WAZUH] Mixed case extension detected (case variation bypass)
Hacking
Web App Attack
๐ต๐น
tiagozip
2025-12-28 10:31:26
(5 months ago)
open proxy
Open Proxy