๐บ๐ธ
TPI-Abuse
2026-09-18 16:59:37
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 12:59:31.098323 2026] [security2:error] [pid 32334:tid 32334] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:52378] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gulftelecom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gulftelecom.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq1t8yGrfSAFZLyeVWUbEwAAABI"], referer: https://gulftelecom.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 10:18:30
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:18:26.333721 2026] [security2:error] [pid 6815:tid 6815] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:48476] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||indoorsfinishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "indoorsfinishing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq0P8kO62TqzMoo5kIO2zwAAAAU"], referer: https://indoorsfinishing.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 23:37:02
(2 days ago)
"GET /wp-admin/ HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:11:56
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:11:50.506915 2026] [security2:error] [pid 21100:tid 21100] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:46118] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||idahouspsa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "idahouspsa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqqVlkqgEP2Pxc2tTt4PNwAAAA8"], referer: https://idahouspsa.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:50:20
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:50:16.637594 2026] [security2:error] [pid 11892:tid 11892] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:34996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thestardance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thestardance.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqo8KBKQZvonEmV7WO6qvAAAAAE"], referer: https://thestardance.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:50:40
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:50:36.425550 2026] [security2:error] [pid 11166:tid 11166] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:57666] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geceindia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geceindia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqm9rGE39cPbpsDU00T7ugAAAAY"], referer: https://geceindia.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:48:30
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:48:24.638977 2026] [security2:error] [pid 12311:tid 12311] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:57778] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqmS-A3UX7TvdYoXsULSAwAAAAE"], referer: https://gonzalez.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 04:45:31
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 00:45:26.775448 2026] [security2:error] [pid 18139:tid 18139] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:33550] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chameleonpcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chameleonpcs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqI15nGT9YEpDbxvsKGMWwAAABA"], referer: https://chameleonpcs.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 03:00:26
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 23:00:18.338855 2026] [security2:error] [pid 19140:tid 19140] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:34952] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mailbox.krakowski.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mailbox.krakowski.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aqIdQt4YfVN_hLpU7paQnwAAAAg"], referer: https://mailbox.krakowski.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-09-10 02:45:02
(1 week ago)
2026/09/10 02:44:37 "GET /wp-admin/ HTTP/1.1"
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-10 01:50:04
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-10 01:28:32
(1 week ago)
2803:e140:1f1:ee90:2649:8839:dec8:86ae - - [10/Sep/2026:03:27:11 +0200] "GET /wp-json/wp/v2/users HT ...
show more
2803:e140:1f1:ee90:2649:8839:dec8:86ae - - [10/Sep/2026:03:27:11 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 404 4585 "https://[site]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2803:e140:1f1:ee90:2649:8839:dec8:86ae - - [10/Sep/2026:03:27:27 +0200] "POST /wp-login.php HTTP/1.1" 404 940 "https://[site]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2803:e140:1f1:ee90:2649:8839:dec8:86ae - - [10/Sep/2026:03:27:43 +0200] "GET /wp-admin/ HTTP/1.1" 404 821 "https://[site]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2803:e140:1f1:ee90:2649:8839:dec8:86ae - - [10/Sep/2026:03:27:59 +0200] "POST /wp-login.php HTTP/1.1" 404 940 "https://[site]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/53
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-10 01:02:01
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 21:01:54.119129 2026] [security2:error] [pid 5964:tid 5964] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:35382] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||washburn-books.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "washburn-books.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqIBgjRKxtoTtDbF2Qa9QgAAAAY"], referer: https://washburn-books.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 23:34:16
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:34:13.346426 2026] [security2:error] [pid 20445:tid 20445] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:52314] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marinestorage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marinestorage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqHs9e2im_gOPPhRY9N3XQAAAAI"], referer: https://marinestorage.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 22:59:19
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown ...
show more
(mod_security) mod_security (id:225170) triggered by 2803:e140:1f1:ee90:2649:8839:dec8:86ae (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 18:59:14.670292 2026] [security2:error] [pid 3383:tid 3383] [client 2803:e140:1f1:ee90:2649:8839:dec8:86ae:53596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||red-jacket.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "red-jacket.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqHkwgEzN1KivY3uA4wVXgAAAAQ"], referer: https://red-jacket.com
show less
Brute-Force
Bad Web Bot
Web App Attack