π©πͺ
stinpriza
2026-09-20 23:36:40
(5 hours ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 20:00:39
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:00:31.565688 2026] [security2:error] [pid 4470:tid 4470] [client 217.154.183.143:58970] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bamedica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arA7X3x60BoEPQe_gZvpiAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
DocNetzwerk
2026-09-20 19:15:55
(10 hours ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 217.154.183.143 (ES/Spain/ip217-154-18 ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 217.154.183.143 (ES/Spain/ip217-154-183-143.pbiaas.com)
show less
Brute-Force
π«π·
masterguru
2026-09-20 14:42:54
(14 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
πΊπΈ
TPI-Abuse
2026-09-20 13:34:42
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:34:36.072046 2026] [security2:error] [pid 7930:tid 7930] [client 217.154.183.143:49002] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lenorasflowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lenorasflowers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq_g7EW9412yFfDxfCA7UAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
taivas.nl
2026-09-20 11:02:12
(18 hours ago)
Bad_requests
Bad Web Bot
π³π±
maxxsense
2026-09-20 00:32:20
(1 day ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 217.154.183.143 (ES/Spain/ip217-154-18 ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 217.154.183.143 (ES/Spain/ip217-154-183-143.pbiaas.com)
show less
Brute-Force
π©πͺ
maxpower
2026-09-19 22:43:58
(1 day ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 217.154.183.143 (ES/Spain/ip217-154-183-143.pb ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 217.154.183.143 (ES/Spain/ip217-154-183-143.pbiaas.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 217.154.183.143 - - [20/Sep/2026:00:43:57 +0200] "GET /wp-json/wp/v2/users HTTP/2.0" 200 4819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0" "217.154.183.143" host=www.consorzioaet.it
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-19 22:29:10
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 18:29:07.204145 2026] [security2:error] [pid 28902:tid 28902] [client 217.154.183.143:53954] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inquisitivequincie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inquisitivequincie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8MszPrnZ3lJSmrdIdtUgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-19 16:59:48
(1 day ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
πͺπΈ
robotstxt
2026-09-19 14:57:34
(1 day ago)
217.154.183.143 - - [19/Sep/2026:14:56:32 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 ...
show more
217.154.183.143 - - [19/Sep/2026:14:56:32 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0" "-" edge="217.154.183.143"
217.154.183.143 - - [19/Sep/2026:14:56:37 +0000] "GET /?author=3 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0" "-" edge="217.154.183.143"
217.154.183.143 - - [19/Sep/2026:14:56:37 +0000] "GET /?author=4 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0" "-" edge="217.154.183.143"
217.154.183.143 - - [19/Sep/2026:14:56:37 +0000] "GET /?author=5 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0" "-" edge="217.154.183.143"
217.154.183.143 - - [19/Sep/2026:14:56:37 +0000] "GET /?author=6 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0" "-" edge="217.154.183.143"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 14:00:06
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 10:00:02.102197 2026] [security2:error] [pid 16815:tid 16815] [client 217.154.183.143:48980] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||comobarbershop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "comobarbershop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6VYvdcDcWJxXQ_jJRayAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-19 13:56:55
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 13:22:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 09:22:02.274465 2026] [security2:error] [pid 9717:tid 9734] [client 217.154.183.143:35602] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pwihatah.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pwihatah.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6Mev9rW0Rx4ZMy4sHIgQAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 11:50:44
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 217.154.183.143 (ip217-154-183-143.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:50:39.575185 2026] [security2:error] [pid 27637:tid 27637] [client 217.154.183.143:33562] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||seagrovesrealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "seagrovesrealty.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq53D0DHOm1h_Sx2OFAZnQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack