๐บ๐ธ
TPI-Abuse
2026-06-21 20:05:12
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 16:05:05.684936 2026] [security2:error] [pid 7540:tid 7540] [client 217.149.7.253:54480] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cajunpicasso.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cajunpicasso.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajhD8ZKrVK5NNSJx_GzmAwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 06:10:02
(2 weeks ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 21:50:25
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 17:50:20.322462 2026] [security2:error] [pid 1529:tid 1529] [client 217.149.7.253:40336] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.difusionens.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.difusionens.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aiXnnCkuOjS-i6TcrsjHkQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 16:17:59
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 12:17:51.345535 2026] [security2:error] [pid 30346:tid 30346] [client 217.149.7.253:59240] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.esysapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.esysapps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiWZrwgUPTXAO7lS28KO8wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 23:49:43
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 19:49:39.840764 2026] [security2:error] [pid 10833:tid 10986] [client 217.149.7.253:59370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rawhabitat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rawhabitat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiSyE-DOe4jaiIkl7-LfSQAAAZE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 16:46:49
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 12:46:45.952765 2026] [security2:error] [pid 27288:tid 27304] [client 217.149.7.253:48696] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.datuinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.datuinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiRO9d80SbaQ97QHutiRQwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 01:55:43
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 21:55:35.407844 2026] [security2:error] [pid 20269:tid 20269] [client 217.149.7.253:59176] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonnesfrequences.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonnesfrequences.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiN-FxICUnfvA6jPDh4U6QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-06 00:21:26
(2 weeks ago)
[redacted] 217.149.7.253 - - [06/Jun/2026:02:21:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 217.149.7.253 - - [06/Jun/2026:02:21:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0"
[redacted] 217.149.7.253 - - [06/Jun/2026:02:21:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0"
[redacted] 217.149.7.253 - - [06/Jun/2026:02:21:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:40.0) Gecko/20100101 Firefox/40.0"
[redacted] 217.149.7.253 - - [06/Jun/2026:02:21:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:98.0) Gecko/20100101 Firefox/98.0"
[redacted] 217.149.7.253 - - [06/Jun/2026:02:21:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0"
[redacted] 217.149.7.2
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 20:53:49
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 16:53:41.801029 2026] [security2:error] [pid 6515:tid 6515] [client 217.149.7.253:38730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.stoneybluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.stoneybluff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiM3VTCYvOGt0lPk6vbKWgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 20:02:06
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 16:01:59.031462 2026] [security2:error] [pid 3976:tid 3976] [client 217.149.7.253:47136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||altoshp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "altoshp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiMrN7kVun71VaSk8nVaXwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 18:10:18
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 14:10:13.320268 2026] [security2:error] [pid 28974:tid 28974] [client 217.149.7.253:36890] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hydrusdetergents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hydrusdetergents.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agYQBbxGgANNofBSH9uzfwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 16:49:58
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 12:49:48.889552 2026] [security2:error] [pid 3561:tid 3588] [client 217.149.7.253:40072] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frannykingsmith.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frannykingsmith.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agX9LIilVATAfHOAAp9KCwAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 15:54:39
(1 month ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
LRob.fr
2026-05-14 15:15:12
(1 month ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-14 13:29:25
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 217.149.7.253 (srv07253.servatica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 09:29:17.002323 2026] [security2:error] [pid 16875:tid 16875] [client 217.149.7.253:39442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||plazahacienda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "plazahacienda.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agXOLPUoq7R9RTi-hfH_zgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack