Anonymous
2026-06-22 21:59:26
(23 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 20:22:40
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 16:22:33.069674 2026] [security2:error] [pid 24671:tid 24671] [client 217.160.22.146:49936] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ruthbalser.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ruthbalser.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajmZibRueggVwGz6x3RVeQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 17:10:03
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 13:09:54.453708 2026] [security2:error] [pid 22131:tid 22131] [client 217.160.22.146:47802] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.t9teamsportinggoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.t9teamsportinggoods.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajlsYtmkSGRMsH_nMATjeAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 11:53:48
(1 day ago)
[ns41.kdns.gr] httpd-suspicious-path: sites=apnoia.gr; logs=/var/log/httpd/domains/apnoia.gr.log; sa ...
show more
[ns41.kdns.gr] httpd-suspicious-path: sites=apnoia.gr; logs=/var/log/httpd/domains/apnoia.gr.log; samples=/wp-json/wp/v2/users | /?author=1 | /?author=2
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 11:53:15
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 07:53:07.125909 2026] [security2:error] [pid 32474:tid 32474] [client 217.160.22.146:34132] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fundaciondamashcc.org.ec|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fundaciondamashcc.org.ec"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkiI-lN_YjzZkrHwW90mwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 04:25:59
(1 day ago)
217.160.22.146 - - > www.allacasadilucia.it [22/Jun/2026:06:25:56 +0200] "POST /xmlrpc.php HTTP/1.1" ...
show more
217.160.22.146 - - > www.allacasadilucia.it [22/Jun/2026:06:25:56 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" "-"
217.160.22.146 - - > www.allacasadilucia.it [22/Jun/2026:06:25:57 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0" "-"
217.160.22.146 - - > www.allacasadilucia.it [22/Jun/2026:06:25:58 +0200] "POST /wp-login.php HTTP/1.1" 200 2438 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:82.0) Gecko/20100101 Firefox/82.0" "-"
217.160.22.146 - - > www.allacasadilucia.it [22/Jun/2026:06:25:58 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0" "-"
217.160.22.146 - - > www.allacasadilucia.it [22/Jun/2026:06:25:59 +0200] "POST /wp-login.php HTTP/1.1" 200 2438 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:69.0) Gecko/20100101 Firefox/69.0" "-"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 03:47:12
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 23:47:06.004682 2026] [security2:error] [pid 31833:tid 31833] [client 217.160.22.146:38026] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tracytappan.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajiwOna_2SbuqaCJY-j28wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 23:56:12
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 19:56:06.591804 2026] [security2:error] [pid 24561:tid 24561] [client 217.160.22.146:34158] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.americanexportimport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.americanexportimport.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajh6FrmIYyTOAV05Zl2pSgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-20 22:29:52
(2 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-19 22:29:33
(3 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 05:10:55
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 01:10:50.358130 2026] [security2:error] [pid 16459:tid 16459] [client 217.160.22.146:39114] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pixelspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pixelspective.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajTPWlC1ISKzvFQcppsLgAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 01:01:22
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 21:01:16.692311 2026] [security2:error] [pid 25563:tid 25563] [client 217.160.22.146:35740] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||shelbysmoak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "shelbysmoak.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajSU3N_Yu42eX2cpC0RF_QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 20:46:39
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 16:46:35.022438 2026] [security2:error] [pid 5090:tid 5090] [client 217.160.22.146:51812] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.magacine.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.magacine.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "ajRZKxMW2ZVL1Ry-etK-dgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 00:20:46
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 20:20:41.900651 2026] [security2:error] [pid 26200:tid 26200] [client 217.160.22.146:34436] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.the-it-man.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.the-it-man.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahjb2aV88b28I8tmFiZgIQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 03:38:07
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.22.146 (ip217-160-22-146.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 23:38:01.338268 2026] [security2:error] [pid 10280:tid 10280] [client 217.160.22.146:37966] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lockdownclaim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lockdownclaim.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahZnGUs5uvxuV4wAB8MrcAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack