๐บ๐ธ
TPI-Abuse
2026-09-20 18:46:41
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosti ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosting.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:46:32.346974 2026] [security2:error] [pid 7856:tid 7856] [client 2a00:1bd0:0:9209:213:132:222:91:55382] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bamedica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arAqCCfLKOtOkemnkbV5_gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-20 10:14:59
(10 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2a00:1bd0:0:9209:213:132:222:91 (-): 1 in the ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2a00:1bd0:0:9209:213:132:222:91 (-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a00:1bd0:0:9209:213:132:222:91 - - [20/Sep/2026:12:14:56 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12092 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0" "-" host=www.coget.eu
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-20 02:32:11
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosti ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosting.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 22:32:06.254232 2026] [security2:error] [pid 2581:tid 2581] [client 2a00:1bd0:0:9209:213:132:222:91:33180] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soonerstone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9FprLNc6oRO-iBrarLigAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 01:22:59
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosti ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosting.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:22:54.987606 2026] [security2:error] [pid 20681:tid 20681] [client 2a00:1bd0:0:9209:213:132:222:91:44230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lenorasflowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lenorasflowers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq81bttWgxAnMFIqdq1GjgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 22:54:45
(22 hours ago)
2026-09-20T00:54:29.643860+02:00 wordpress(www.katrinzeidler.com)[2666206]: Blocked user enumeratio ...
show more
2026-09-20T00:54:29.643860+02:00 wordpress(www.katrinzeidler.com)[2666206]: Blocked user enumeration attempt from 2a00:1bd0:0:9209:213:132:222:91
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 21:23:25
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosti ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosting.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 17:23:16.350278 2026] [security2:error] [pid 13933:tid 13933] [client 2a00:1bd0:0:9209:213:132:222:91:51990] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cubbylure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cubbylure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq79RCw9G9JmKYTqasPMSQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 20:37:56
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosti ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosting.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 16:37:52.852055 2026] [security2:error] [pid 3899:tid 3899] [client 2a00:1bd0:0:9209:213:132:222:91:51462] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.stantontownship.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.stantontownship.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7yoF_Cc-CWWmsowjz8KQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 20:03:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosti ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosting.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 16:03:48.121453 2026] [security2:error] [pid 5667:tid 5667] [client 2a00:1bd0:0:9209:213:132:222:91:54730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adlc18.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adlc18.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7qpCjnqhboTMjOLRsIuwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-19 16:54:19
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
๐ฉ๐ช
maxpower
2026-09-19 14:34:46
(1 day ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2a00:1bd0:0:9209:213:132:222:91 (-): 1 in the ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2a00:1bd0:0:9209:213:132:222:91 (-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a00:1bd0:0:9209:213:132:222:91 - - [19/Sep/2026:16:34:41 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12005 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0" "-" host=mamideco.com
show less
Port Scan
๐ซ๐ฎ
YF
2026-09-18 04:01:00
(2 days ago)
WordPress author enumeration
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 16:29:15
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users (+1 more) | query: author=1 | 2026-09-17 16:29 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 13:09:22
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosti ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosting.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:09:16.987562 2026] [security2:error] [pid 19798:tid 19936] [client 2a00:1bd0:0:9209:213:132:222:91:46912] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nicholsinvest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nicholsinvest.com"] [uri "/ria-2015/wp-json/wp/v2/users"] [unique_id "aqvmfNYvbzONyL5caX4KUgAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 10:21:35
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosti ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1bd0:0:9209:213:132:222:91 (plesk9.nlhosting.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:21:27.739568 2026] [security2:error] [pid 5323:tid 5323] [client 2a00:1bd0:0:9209:213:132:222:91:39896] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgesmarina.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqu_J2jwTx7H33pIekD_vgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-17 09:53:52
(3 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2a00:1bd0:0:9209:213:132:222:91 (-): 1 in the ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2a00:1bd0:0:9209:213:132:222:91 (-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a00:1bd0:0:9209:213:132:222:91 - - [17/Sep/2026:11:53:50 +0200] "GET /wp-json/wp/v2/users HTTP/2.0" 200 4817 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" "2a00:1bd0:0:9209:213:132:222:91" host=lasfiziosapizzeria.it
show less
Port Scan