🇳🇱
ipoac.nl
2026-09-09 03:30:26
(11 minutes ago)
2026-09-09T05:30:24.419176+02:00 ipoac.nl wordpress(-)-: Authentication failure for-from 222.155.221 ...
show more
2026-09-09T05:30:24.419176+02:00 ipoac.nl wordpress(-)-: Authentication failure for-from 222.155.221.152
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:29:46
(11 minutes ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:29:38.787881 2026] [security2:error] [pid 5485:tid 5485] [client 222.155.221.152:56820] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.toepferlab.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.toepferlab.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDSohIu7FK4-wSP9w3Q3gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:12:30
(28 minutes ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:12:26.154533 2026] [security2:error] [pid 26863:tid 26863] [client 222.155.221.152:58646] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||spacebooger.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "spacebooger.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDOmqv6pXdV2LGA3F2k3wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:55:51
(45 minutes ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:55:44.697540 2026] [security2:error] [pid 15936:tid 15936] [client 222.155.221.152:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.southernbroadcast.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDKsP3iVuIwOHq6dZAB9AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:25:27
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:25:20.385998 2026] [security2:error] [pid 12770:tid 12770] [client 222.155.221.152:33398] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.zost.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.zost.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDDkMCowdcA6C370srXEQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:00:57
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:00:49.991508 2026] [security2:error] [pid 8286:tid 8286] [client 222.155.221.152:56264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zeetec.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zeetec.nl"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC90X_qW6S6MhHJVUBLRgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:25:21
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:25:15.263715 2026] [security2:error] [pid 6087:tid 6087] [client 222.155.221.152:57570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ww1.clcmillvale.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ww1.clcmillvale.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC1e8PYcZKIUzPnT3XerQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:40:06
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:39:59.175136 2026] [security2:error] [pid 536299:tid 536409] [client 222.155.221.152:48408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hmpdecors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hmpdecors.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCq37dqgKcUbA4wGrJHBQAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 00:27:08
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:23:42
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:23:37.775962 2026] [security2:error] [pid 14951:tid 14951] [client 222.155.221.152:34772] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newcitypark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newcitypark.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCnCbyEHIjwGyrTAadHugAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:49:32
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:49:29.153928 2026] [security2:error] [pid 25104:tid 25104] [client 222.155.221.152:36326] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||difusionens.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "difusionens.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCfCac091CVUQ5y1qRiiAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:31:36
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:31:32.270189 2026] [security2:error] [pid 17365:tid 17365] [client 222.155.221.152:40494] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marklex.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marklex.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCa1OFzfJOErvv02Y0L0gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 23:17:47
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:47:17
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb. ...
show more
(mod_security) mod_security (id:225170) triggered by 222.155.221.152 (222-155-221-152-fibre.sparkbb.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:47:10.927170 2026] [security2:error] [pid 28417:tid 28417] [client 222.155.221.152:56038] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bostonmarathonstories.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bostonmarathonstories.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCQbj99mwVU7DC-NmoxTgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 22:19:19
(5 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack