Hazzard
2025-07-09 14:34:25
(11 hours ago)
(wordpress) Failed wordpress login from 2607:f298:6:a014::f0a:8f77 (US/United States/-/-/dreamsoftbv ... show more (wordpress) Failed wordpress login from 2607:f298:6:a014::f0a:8f77 (US/United States/-/-/dreamsoftbv.com/[redacted]) show less
Brute-Force
TPI-Abuse
2025-07-09 08:06:28
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 09 04:06:23.159215 2025] [security2:error] [pid 7675:tid 7675] [client 2607:f298:6:a014::f0a:8f77:42346] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tell-me-first.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tell-me-first.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aG4i_1mZNHoxz_HYYBs1KAAAAAA"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-09 04:27:27
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 09 00:27:19.979782 2025] [security2:error] [pid 22970:tid 22970] [client 2607:f298:6:a014::f0a:8f77:35712] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bryjer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bryjer.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aG3vpwNwaARSbMqPZpfnGQAAAAM"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-08 22:23:22
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 18:23:16.711847 2025] [security2:error] [pid 6889:tid 6917] [client 2607:f298:6:a014::f0a:8f77:37394] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||slingshotpro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "slingshotpro.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aG2aVHwCE7F6a8bk_rZFvgAAAYU"] show less
Brute-Force
Bad Web Bot
Web App Attack
SOC [GOLINE SA]
2025-07-08 22:02:08
(1 day ago)
FortiGate detected IPS attack from IPv6 address 2607:f298:6:a014::f0a:8f77
Hacking
TPI-Abuse
2025-07-08 12:07:44
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 08:07:39.021146 2025] [security2:error] [pid 24647:tid 24647] [client 2607:f298:6:a014::f0a:8f77:49350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jasonmcquain.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jasonmcquain.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aG0KCz9XUHjyYbWLvAWGHwAAAAY"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-08 10:03:16
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 06:03:13.073466 2025] [security2:error] [pid 25420:tid 25420] [client 2607:f298:6:a014::f0a:8f77:36410] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||belgiophar.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "belgiophar.info"] [uri "/wp-json/wp/v2/users"] [unique_id "aGzs4fGfBsZEyACeOmzqFQAAAAI"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-08 09:36:03
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 05:35:55.630889 2025] [security2:error] [pid 12823:tid 12823] [client 2607:f298:6:a014::f0a:8f77:35980] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||manosentuayuda.imerka.com.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "manosentuayuda.imerka.com.mx"] [uri "/wp-json/wp/v2/users"] [unique_id "aGzme9cNaBThKgaxvawS5wAAAAM"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-08 06:48:17
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 02:48:12.478068 2025] [security2:error] [pid 21431:tid 21431] [client 2607:f298:6:a014::f0a:8f77:57034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||herrell.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "herrell.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aGy_LIAmttQy32t9L9nKqgAAAAQ"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-08 02:26:23
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 07 22:26:16.326828 2025] [security2:error] [pid 19833:tid 19833] [client 2607:f298:6:a014::f0a:8f77:59830] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dossat.cl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dossat.cl"] [uri "/wp-json/wp/v2/users"] [unique_id "aGyByE2ACsn2R6b6uAlNUgAAABA"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-08 01:18:49
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 07 21:18:40.978583 2025] [security2:error] [pid 11231:tid 11231] [client 2607:f298:6:a014::f0a:8f77:50312] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pakistanvision.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pakistanvision.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aGxx8OYOnaTRKLDj_yQrqQAAAAg"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-07 20:04:56
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 07 16:04:51.891894 2025] [security2:error] [pid 23501:tid 23501] [client 2607:f298:6:a014::f0a:8f77:57668] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||indyham.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "indyham.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aGwoY-o9HtLR8bRzGt9VTAAAABQ"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-07 16:58:52
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 07 12:58:45.976197 2025] [security2:error] [pid 29372:tid 29372] [client 2607:f298:6:a014::f0a:8f77:56564] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||comsew.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "comsew.com.au"] [uri "/wp-json/wp/v2/users"] [unique_id "aGv8xU9SwoRUDuRNCxsT3wAAAAM"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-07 15:47:21
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 07 11:47:14.416999 2025] [security2:error] [pid 19406:tid 19406] [client 2607:f298:6:a014::f0a:8f77:58948] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dogandponyband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dogandponyband.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aGvsAukPH4NZR5nPlAs51AAAACo"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-07-07 14:08:54
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 ... show more (mod_security) mod_security (id:225170) triggered by 2607:f298:6:a014::f0a:8f77 (dreamsoftbv.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 07 10:08:50.114090 2025] [security2:error] [pid 15952:tid 15952] [client 2607:f298:6:a014::f0a:8f77:39952] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michelehoop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aGvU8mOhUYjkMMxa33sZtwAAAA8"] show less
Brute-Force
Bad Web Bot
Web App Attack