🇺🇸
nationaleventpros.com
2026-06-14 17:52:26
(2 days ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-05-29 09:12:32
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 05:12:29.172579 2026] [security2:error] [pid 11765:tid 11765] [client 213.108.0.162:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aslanhan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aslanhan.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahlYfQ4rjfxLGftqJHWuvAAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-29 00:59:27
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 20:59:20.761749 2026] [security2:error] [pid 7043:tid 7043] [client 213.108.0.162:61853] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||exit10band.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "exit10band.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahjk6Ih7oIVwOQmL8dEG1gAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-27 07:11:20
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 03:11:14.612417 2026] [security2:error] [pid 19987:tid 19987] [client 213.108.0.162:48013] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jimcameron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jimcameron.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahaZEkETgKusf5JD_-pNLwAAAB4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-18 16:24:01
(6 months ago)
wordpress-trap
Web App Attack
🇺🇸
TPI-Abuse
2025-09-04 17:42:37
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 04 13:42:30.118181 2025] [security2:error] [pid 5153:tid 5153] [client 213.108.0.162:25369] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hotjive.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hotjive.com"] [uri "/"] [unique_id "aLnPhraYd7nUa7iWf5uAgAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
london2038.com
2025-07-10 05:44:46
(11 months ago)
Detected by WP fail2ban
2025-07-10T07:44:45.053283+02:00 wordpress: Authentication attempt from 213. ...
show more
Detected by WP fail2ban
2025-07-10T07:44:45.053283+02:00 wordpress: Authentication attempt from 213.108.0.162
show less
Brute-Force
Web App Attack
Anonymous
2025-05-30 01:50:13
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-05-27 13:00:40
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-25 09:03:06
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-17 10:00:00
(1 year ago)
“BruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried us ...
show more
“BruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried users are invalid and random.Most Tried Users are Guest and Admin. n type=event subtype=vpn level=alert action=ssl-login-fail msg=SSL user failed to logged in logdesc=SSL VPN login fail user=datadevscan02 group=N/A tunnelid=0 tunneltype=ssl-web dst_host=N/A reason=sslvpn_login_unknown_user”
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2025-04-17 10:00:00
(1 year ago)
“BruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried us ...
show more
“BruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried users are invalid and random.Most Tried Users are Guest and Admin. n type=event subtype=vpn level=alert action=ssl-login-fail msg=SSL user failed to logged in logdesc=SSL VPN login fail user=datadevscan02 group=N/A tunnelid=0 tunneltype=ssl-web dst_host=N/A reason=sslvpn_login_unknown_user “
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2025-04-15 23:00:43
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 15 19:00:37.809141 2025] [security2:error] [pid 1122:tid 1125] [client 213.108.0.162:11317] [client 213.108.0.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rpiusa.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rpiusa.net"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_7lFRepYJz5k6bEZqSMYwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
MAGIC
2025-04-15 15:35:17
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2025-04-06 17:50:11
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 06 13:50:06.171992 2025] [security2:error] [pid 2762:tid 2762] [client 213.108.0.162:25387] [client 213.108.0.162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||baselineledsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "baselineledsolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_K-ztn4t7_ARhzxid7RNgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack