๐ฉ๐ช
london2038.com
2026-08-12 08:34:48
(1 month ago)
Probing for exploits
2407:3640:2336:2728::1 - - [12/Aug/2026:10:34:39 +0200] "GET /wp-login.php HTTP ...
show more
Probing for exploits
2407:3640:2336:2728::1 - - [12/Aug/2026:10:34:39 +0200] "GET /wp-login.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
2407:3640:2336:2728::1 - - [12/Aug/2026:10:34:44 +0200] "POST /wp-login.php HTTP/2.0" 301 0 "https://v97746.<REDACTED>/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 07:42:00
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 03:41:53.277791 2026] [security2:error] [pid 3445209:tid 3445209] [client 2407:3640:2336:2728::1:43728] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||expresstires.us.jbcllcnet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "expresstires.us.jbcllcnet.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "anwjwWLOcptflrRX5hE5bQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 23:33:56
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 19:33:52.546373 2026] [security2:error] [pid 2169087:tid 2169087] [client 2407:3640:2336:2728::1:44342] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "capriexpress.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "anuxYEw-3_HRF8juA2e-WQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-11 22:34:02
(1 month ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-08-11 22:10:05
(1 month ago)
Wordfence waf block on registrymatters
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-08-11 20:25:57
(1 month ago)
WordPress bruteforce
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 19:25:18
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 15:25:11.437030 2026] [security2:error] [pid 20276:tid 20276] [client 2407:3640:2336:2728::1:40580] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.constructionloansfunding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.constructionloansfunding.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ant3Fyp7ogAdlEVXlMqa3AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 19:04:29
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 15:04:25.282239 2026] [security2:error] [pid 3886:tid 3923] [client 2407:3640:2336:2728::1:60156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||maroontribe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "maroontribe.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "antyOTeh49Gcb_DXQLqlRQAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 13:25:34
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 09:25:27.857898 2026] [security2:error] [pid 2473803:tid 2473803] [client 2407:3640:2336:2728::1:42586] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talkingmess.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talkingmess.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ansix3PjO9hL66caXLZ6vQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 13:01:50
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 09:01:43.670693 2026] [security2:error] [pid 3735476:tid 3735476] [client 2407:3640:2336:2728::1:39646] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mchen-arch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mchen-arch.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ansdN8-kMlYedwdlwzzBWAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-08-11 13:00:12
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /wp-json/wp/v2/users/me
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-11 12:17:16
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 08:17:12.574122 2026] [security2:error] [pid 2299555:tid 2299555] [client 2407:3640:2336:2728::1:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "upskirtcrazy.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ansSyKuXH9m7vYepuqNCEgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 11:14:23
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 07:14:17.502743 2026] [security2:error] [pid 847588:tid 847588] [client 2407:3640:2336:2728::1:36136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jmichaelpope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jmichaelpope.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ansECT8v1seYbgbOVLDyZQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 10:35:21
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 06:35:17.430885 2026] [security2:error] [pid 17029:tid 17029] [client 2407:3640:2336:2728::1:60344] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dancingbearprinting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dancingbearprinting.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "anr65bRiKSaPwwoumg_HugAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 09:55:44
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2407:3640:2336:2728::1 (vmi3362728.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 05:55:35.551367 2026] [security2:error] [pid 10437:tid 10437] [client 2407:3640:2336:2728::1:54602] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cnphilos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cnphilos.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "anrxl4ZmysTqtjt1sT5YSwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack