πΊπΈ
TPI-Abuse
2026-02-01 13:55:50
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.co ...
show more
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 08:55:43.594996 2026] [security2:error] [pid 10403:tid 10403] [client 23.95.97.164:33784] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||microdot.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "microdot.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aX9bX6bjlXLGujddLVE1DAAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
smithclass.net
2026-02-01 11:50:39
(7 months ago)
Feb 1 11:50:39 gravy wordpress(lallygag.net)[914113]: XML-RPC authentication attempt for unknown us ...
show more
Feb 1 11:50:39 gravy wordpress(lallygag.net)[914113]: XML-RPC authentication attempt for unknown user msmith from 23.95.97.164
...
show less
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2026-02-01 11:07:16
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.co ...
show more
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:07:08.884717 2026] [security2:error] [pid 29432:tid 29432] [client 23.95.97.164:50837] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fastpc.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fastpc.biz"] [uri "/wp-json/wp/v2/users"] [unique_id "aX8z3L-NfRWi126LY8HlYQAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-01 10:34:00
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.co ...
show more
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 05:33:52.562003 2026] [security2:error] [pid 22972:tid 22972] [client 23.95.97.164:49651] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||phlippo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "phlippo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX8sEF5oPBKK5fosbtbwGwAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-01 09:52:54
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.co ...
show more
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 04:52:48.046000 2026] [security2:error] [pid 17226:tid 17226] [client 23.95.97.164:52139] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wizind.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wizind.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX8icI40zII1h0guhqaXvgAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-01 07:26:41
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.co ...
show more
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 02:26:35.184165 2026] [security2:error] [pid 32251:tid 32251] [client 23.95.97.164:39772] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nightowlprinting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nightowlprinting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX8AKyoktVDBEA09ldPFngAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-01-08 15:39:20
(8 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-08 04:40:44
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.co ...
show more
(mod_security) mod_security (id:225170) triggered by 23.95.97.164 (23-95-97-164-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 23:40:37.140604 2026] [security2:error] [pid 28346:tid 28346] [client 23.95.97.164:49618] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jcsforwarding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jcsforwarding.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aV81RUS-vmLIIYSZKzcxhQAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
ingrowrook
2025-10-09 07:17:00
(11 months ago)
Cloud Application User Account Credential Stuffing
Hacking
Brute-Force
π©πͺ
Packets-Decreaser.NET
2025-09-05 20:14:09
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-08-11 09:39:24
(1 year ago)
Credential Stuffing attacks against Microsoft 365
Brute-Force
Anonymous
2025-07-23 16:32:47
(1 year ago)
Failed login attempt detected by Fail2Ban in recidive jail
Brute-Force
Anonymous
2025-06-19 08:55:34
(1 year ago)
Credential Stuffing attacks against Microsoft 365
Brute-Force
π©πͺ
FeG Deutschland
2025-05-30 07:05:03
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
Anonymous
2025-05-24 20:24:42
(1 year ago)
Credential Stuffing attacks against Microsoft 365
Brute-Force