๐บ๐ธ
TPI-Abuse
2026-06-11 18:55:14
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 14:55:10.280995 2026] [security2:error] [pid 23608:tid 23608] [client 217.160.228.20:42522] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.teleplussolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.teleplussolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aisEjvMdxEfcWfabaXpSxgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 08:40:30
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 04:40:22.512258 2026] [security2:error] [pid 1552:tid 1552] [client 217.160.228.20:47506] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sizefinder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sizefinder.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aip0dhirj0lqDFNgEGROkwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-10 22:36:00
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 10:43:20
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 06:43:16.240592 2026] [security2:error] [pid 4648:tid 4648] [client 217.160.228.20:59572] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fiasdesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fiasdesigns.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aik_xAutb2h2tPxS99ffCAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 21:04:40
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 17:04:32.821203 2026] [security2:error] [pid 31630:tid 31630] [client 217.160.228.20:60084] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.scswat.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.scswat.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aih_4CJZRRxjsJWm98O8dQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-09 07:09:54
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 10:44:33
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 06:44:29.690494 2026] [security2:error] [pid 10788:tid 10788] [client 217.160.228.20:53922] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.michelehoop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiadDUKYjFkF2uLA8qmh4wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 04:03:33
(1 week ago)
[redacted] 217.160.228.20 - - [08/Jun/2026:06:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" " ...
show more
[redacted] 217.160.228.20 - - [08/Jun/2026:06:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0"
[redacted] 217.160.228.20 - - [08/Jun/2026:06:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0"
[redacted] 217.160.228.20 - - [08/Jun/2026:06:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0"
[redacted] 217.160.228.20 - - [08/Jun/2026:06:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:63.0) Gecko/20100101 Firefox/63.0"
[redacted] 217.160.228.20 - - [08/Jun/2026:06:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0"
[redacted] 217.160.228.20 - - [08/Jun/2026:06:03:29 +0200] "POST /xmlrpc.php HTTP/1.1"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 23:04:24
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 19:04:17.013575 2026] [security2:error] [pid 7805:tid 7823] [client 217.160.228.20:55452] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.plumeraproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.plumeraproductions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiSncfRZ2bcVt-YDNxjGSgAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-06 04:54:10
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-06 02:40:51
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 22:40:44.042728 2026] [security2:error] [pid 19848:tid 19848] [client 217.160.228.20:35200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tcomputerguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tcomputerguy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiOIrMCBIylvfURrCmms9gAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-06 00:29:28
(1 week ago)
(wp_login_try) srv103 WP Login Attempt 217.160.228.20 (ES/Spain/ip217-160-228-20.pbiaas.com): 10 in ...
show more
(wp_login_try) srv103 WP Login Attempt 217.160.228.20 (ES/Spain/ip217-160-228-20.pbiaas.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-05 18:37:59
(1 week ago)
Blocked by CSF 13 firewall - Rule: DE/Germany/ip217-160-228-20.pbiaas.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 14:15:10
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:15:01.916344 2026] [security2:error] [pid 2074:tid 2074] [client 217.160.228.20:37044] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.velvetculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.velvetculture.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiLZ5Xiwcn4d32ndNV4UigAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 05:19:16
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 217.160.228.20 (ip217-160-228-20.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 01:19:10.154495 2026] [security2:error] [pid 15618:tid 15618] [client 217.160.228.20:47056] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.naominixon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiEKzlhB8JYYcIyhonDXdQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack