๐บ๐ธ
TPI-Abuse
2026-08-31 08:14:07
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:14:02.336458 2026] [security2:error] [pid 26267:tid 26267] [client 24.199.86.48:52784] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.wp.hotpay.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.wp.hotpay.co"] [uri "/wp-json/wp/v2/users"] [unique_id "apU3yussK2m2TzLJYj9wmgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 08:00:05
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 07:57:18
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:57:13.162586 2026] [security2:error] [pid 9917:tid 9917] [client 24.199.86.48:41132] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||192.64.150.96|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "192.64.150.96"] [uri "/wp-json/wp/v2/users"] [unique_id "apUz2Sk8cO8M0diTft1P5gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-08-31 07:32:57
(4 hours ago)
24.199.86.48 - - [31/Aug/2026:01:32:56 -0600] "POST /wp-login.php HTTP/1.1" 301 162 "-" "Go-http-cli ...
show more
24.199.86.48 - - [31/Aug/2026:01:32:56 -0600] "POST /wp-login.php HTTP/1.1" 301 162 "-" "Go-http-client/1.1"
24.199.86.48 - - [31/Aug/2026:01:32:56 -0600] "POST /wp-login.php HTTP/1.1" 301 162 "-" "Go-http-client/1.1"
24.199.86.48 - - [31/Aug/2026:01:32:57 -0600] "POST /wp-login.php HTTP/1.1" 301 162 "-" "Go-http-client/1.1"
...
show less
Brute-Force
๐ฎ๐ณ
ygohel18
2026-08-31 07:30:02
(4 hours ago)
WP Advanced Login Guardian: 24h escalation hard lock threshold exceeded
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-31 07:20:27
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:20:21.377129 2026] [security2:error] [pid 1969:tid 1969] [client 24.199.86.48:55670] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||192.64.150.34|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "192.64.150.34"] [uri "/wp-json/wp/v2/users"] [unique_id "apUrNT9-6zxXRHwaxJiLhAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 04:22:27
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 00:22:20.466022 2026] [security2:error] [pid 19543:tid 19569] [client 24.199.86.48:55984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.supercyprus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.supercyprus.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUBfE46awdR1C9vISD9jAAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 04:01:25
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 00:01:17.656948 2026] [security2:error] [pid 9679:tid 9679] [client 24.199.86.48:35592] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coolcustomweddingproducts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coolcustomweddingproducts.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apT8jVSqI0jmr6BoiiRikwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Rexikon
2026-08-31 03:28:37
(8 hours ago)
24.199.86.48 - - [31/Aug/2026:05:28:34 +0200] "POST /wp-login.php HTTP/1.1" 200 19207 "-" "Go-http-c ...
show more
24.199.86.48 - - [31/Aug/2026:05:28:34 +0200] "POST /wp-login.php HTTP/1.1" 200 19207 "-" "Go-http-client/1.1"
24.199.86.48 - - [31/Aug/2026:05:28:35 +0200] "POST /wp-login.php HTTP/1.1" 200 19207 "-" "Go-http-client/1.1"
24.199.86.48 - - [31/Aug/2026:05:28:35 +0200] "POST /wp-login.php HTTP/1.1" 200 19207 "-" "Go-http-client/1.1"
24.199.86.48 - - [31/Aug/2026:05:28:36 +0200] "POST /wp-login.php HTTP/1.1" 200 19207 "-" "Go-http-client/1.1"
24.199.86.48 - - [31/Aug/2026:05:28:36 +0200] "POST /wp-login.php HTTP/1.1" 200 19207 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Anonymous
2026-08-31 03:02:02
(9 hours ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 02:11:27
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 24.199.86.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 22:11:20.908626 2026] [security2:error] [pid 26951:tid 26951] [client 24.199.86.48:51176] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mlsdirect.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mlsdirect.xyz"] [uri "/wp-json/wp/v2/users"] [unique_id "apTiyD45HkhTGCt9_lvQ7QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-08-31 01:08:21
(10 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ช๐ธ
mescribano
2026-08-31 00:10:02
(11 hours ago)
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-30 23:07:53
(12 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ธ๐ช
vaia.cloud
2026-08-30 23:00:01
(13 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack