🇺🇸
TPI-Abuse
2026-05-03 14:36:29
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.44 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 10:36:25.436714 2026] [security2:error] [pid 9812:tid 9812] [client 213.108.0.44:46677] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theblindmantylertx.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theblindmantylertx.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afddaQPRwvmtEShN9jLC7QAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-24 06:51:15
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.44 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 24 02:51:07.857146 2026] [security2:error] [pid 24633:tid 24633] [client 213.108.0.44:15701] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sierra-broadcasting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sierra-broadcasting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aesS219bpbfYmkrbazSsEAAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-23 18:50:12
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.44 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 14:50:03.987998 2026] [security2:error] [pid 3921873:tid 3921873] [client 213.108.0.44:37761] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||no504.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "no504.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aepp2z0pj3PvTXRlH4GGfQAAABs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
C C
2026-02-23 11:39:58
(3 months ago)
Distributed proxy crawl wave (69 requests, 69 unique IPs in 73 sec)
Bad Web Bot
Web App Attack
🇩🇪
Packets-Decreaser.NET
2025-12-10 14:34:36
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-11-25 15:48:13
(6 months ago)
wordpress-trap
Web App Attack
Anonymous
2025-04-19 15:17:33
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-18 15:14:50
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-17 10:00:00
(1 year ago)
“BruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried us ...
show more
“BruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried users are invalid and random.Most Tried Users are Guest and Admin. n type=event subtype=vpn level=alert action=ssl-login-fail msg=SSL user failed to logged in logdesc=SSL VPN login fail user=datadevscan02 group=N/A tunnelid=0 tunneltype=ssl-web dst_host=N/A reason=sslvpn_login_unknown_user”
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2025-04-17 10:00:00
(1 year ago)
“BruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried us ...
show more
“BruteForce attack on SSL VPN. Appears to be addresses coming from US Datacenters. Most all tried users are invalid and random.Most Tried Users are Guest and Admin. n type=event subtype=vpn level=alert action=ssl-login-fail msg=SSL user failed to logged in logdesc=SSL VPN login fail user=datadevscan02 group=N/A tunnelid=0 tunneltype=ssl-web dst_host=N/A reason=sslvpn_login_unknown_user “
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2025-04-13 03:17:55
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-11 08:39:15
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-01 15:13:19
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-02-11 07:07:02
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-02-10 04:58:32
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH