🇺🇸
TPI-Abuse
2026-08-29 19:17:00
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 15:16:53.147573 2026] [security2:error] [pid 25572:tid 25572] [client 217.131.14.112:59800] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dianedanielsmanning.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dianedanielsmanning.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apMwJVMXPYcnDpPWNcEMjAAAACE"], referer: https://dianedanielsmanning.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
abuseiphack
2026-08-29 12:59:35
(8 hours ago)
Automatic report for brute force attack
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 05:38:40
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:38:34.089128 2026] [security2:error] [pid 3152:tid 3152] [client 217.131.14.112:59744] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jvwebinars.vanemby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jvwebinars.vanemby.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apJwWpTSCupSrI7GhcXvNwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 14:07:14
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:07:11.617460 2026] [security2:error] [pid 2619415:tid 2619439] [client 217.131.14.112:42898] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||miltonthepuppy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "miltonthepuppy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apGWD_WHiFF02DBMg-C5gQAAAUw"], referer: https://miltonthepuppy.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-08-28 10:32:42
(1 day ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-28 05:18:23
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-28 02:54:36
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇲🇹
Malta
2026-08-28 01:20:06
(1 day ago)
217.131.14.112 - - [28/Aug/2026:03:20:05 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
217.131.14.112 - - [28/Aug/2026:03:20:05 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇸
lostswordfish.com
2026-08-27 20:36:03
(2 days ago)
Wordfence waf block on pameganslaw
Web App Attack
🇩🇪
ger-stg-sifi1
2026-08-27 09:23:22
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-26 16:26:11
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇨🇭
4server
2026-08-26 13:04:13
(3 days ago)
[WedAug2615:04:06.2395582026][security2:error][pid445425:tid445481][client217.131.14.112:0]ModSecuri ...
show more
[WedAug2615:04:06.2395582026][security2:error][pid445425:tid445481][client217.131.14.112:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"614\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"marcionetti.es\"][uri\"/xmlrpc.php\"][unique_id\"ao7kRtK7hpRFdUfbtTv4sAAAAFE\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 10:01:37
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:01:33.318373 2026] [security2:error] [pid 30852:tid 30852] [client 217.131.14.112:39986] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michaelkivisto.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michaelkivisto.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao65fSrsj_bH_11Xz6x9RwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 08:30:21
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:30:13.732303 2026] [security2:error] [pid 24141:tid 24141] [client 217.131.14.112:55722] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "d-sinema.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6kFcnRZjN2JUq5TtXu1AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 08:04:29
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 217.131.14.112 (mail.hostidex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:04:22.671575 2026] [security2:error] [pid 10738:tid 10738] [client 217.131.14.112:59282] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.thorndikestudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6eBjz0iDmTQfMG9hB_ZwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack