๐บ๐ธ
TPI-Abuse
2026-05-12 22:56:00
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 18:55:55.151584 2026] [security2:error] [pid 32761:tid 32761] [client 2a01:4f8:231:166e::2:56482] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.monogay.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.monogay.org"] [uri "/wp-json/wp/v2/users"] [unique_id "agOv-y6EdHLOwSrCWJ7h_wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 17:28:27
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 13:28:22.522354 2026] [security2:error] [pid 16438:tid 16438] [client 2a01:4f8:231:166e::2:33650] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.weird.eco|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.weird.eco"] [uri "/wp-json/wp/v2/users"] [unique_id "agNjNgiandQ5owsnWaey2gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 16:05:51
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 12:05:46.227347 2026] [security2:error] [pid 21273:tid 21273] [client 2a01:4f8:231:166e::2:56942] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||erikageyama.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "erikageyama.com"] [uri "/portfolio/wp-json/wp/v2/users"] [unique_id "agNP2qGswgcESHP-em4ipwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 12:13:56
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 08:13:52.004687 2026] [security2:error] [pid 4316:tid 4316] [client 2a01:4f8:231:166e::2:39290] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lemoulinavent.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lemoulinavent.org"] [uri "/wp-json/wp/v2/users"] [unique_id "agMZgGNMhX3mfFz76H0WNQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 11:27:35
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 07:27:29.939382 2026] [security2:error] [pid 5340:tid 5354] [client 2a01:4f8:231:166e::2:39368] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.teritemme.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.teritemme.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agMOodnRfGaAVAbNSmVlDgAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-05-11 12:15:06
(3 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-11 07:49:12
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 03:49:05.009660 2026] [security2:error] [pid 5025:tid 5025] [client 2a01:4f8:231:166e::2:44762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nomorenicenice.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nomorenicenice.net"] [uri "/wp-json/wp/v2/users"] [unique_id "agGJ8VQfxPqXrPXP_exc8gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 04:50:06
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:49:57.339073 2026] [security2:error] [pid 24653:tid 24653] [client 2a01:4f8:231:166e::2:54104] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inverzona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inverzona.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agFf9ctQ7bIfyBcdSs_5UgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 04:01:40
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:231:166e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:01:34.484004 2026] [security2:error] [pid 29369:tid 29369] [client 2a01:4f8:231:166e::2:53774] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||comobarbershop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "comobarbershop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agFUnn6bzJ_DJ4J8vz4q2gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-05-01 22:45:05
(4 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-10-26 17:44:52
(10 months ago)
2a01:4f8:231:166e::2 - - [26/Oct/2025:11:44:52 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Mozil ...
show more
2a01:4f8:231:166e::2 - - [26/Oct/2025:11:44:52 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-10-10 08:46:20
(10 months ago)
2a01:4f8:231:166e::2 - - [10/Oct/2025:11:46:10 +0300] "GET /blog/wp-login.php HTTP/1.1" 404 2872 "ht ...
show more
2a01:4f8:231:166e::2 - - [10/Oct/2025:11:46:10 +0300] "GET /blog/wp-login.php HTTP/1.1" 404 2872 "https://www.reddit.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.2210.133"
2a01:4f8:231:166e::2 - - [10/Oct/2025:11:46:18 +0300] "GET /wp-admin/ HTTP/1.1" 404 2872 "https://www.reddit.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/122.0"
...
show less
Web App Attack
Anonymous
2025-09-30 12:38:48
(11 months ago)
Failed Wordpress login
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-09-22 00:53:58
(11 months ago)
Wordpress attack: Submitted data to wp-login.php prior getting page content, attempt blocked. POST c ...
show more
Wordpress attack: Submitted data to wp-login.php prior getting page content, attempt blocked. POST counter 1 is greater than GET counter 0 for /wp-login.php by 2a01:4f8:231:166e::2.
show less
Web Spam
๐บ๐ธ
myagent.site
2025-09-21 19:47:20
(11 months ago)
Blocked authentication attempt for banned user: admin
Hacking