🇺🇸
TPI-Abuse
2026-09-05 07:24:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 03:24:30.632208 2026] [security2:error] [pid 20695:tid 20695] [client 2a02:1778::113:2c0:48416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.michaelthompson.biz"] [uri "/wp-config.php.bak"] [unique_id "apvDrlAyn1QUtLcY3AtAiwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 23:10:03
(13 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-02 21:29:21
(2 days ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
mawan
2024-12-28 00:38:24
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
🇩🇪
Ba-Yu
2024-12-22 08:27:26
(1 year ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
🇸🇬
Cloudkul Cloudkul
2024-12-21 21:15:07
(1 year ago)
Multiple unauthorized attempts to access web resources
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2024-12-05 16:30:29
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 05 11:30:22.285482 2024] [security2:error] [pid 31060:tid 31214] [client 2a02:1778::113:2c0:38372] [client 2a02:1778::113:2c0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.gilesrentalcars.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.gilesrentalcars.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z1HVHtoamouYuCrddE4l_wAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-12-05 16:13:53
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 05 11:13:45.418243 2024] [security2:error] [pid 3282:tid 3282] [client 2a02:1778::113:2c0:44402] [client 2a02:1778::113:2c0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.prayers4america.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.prayers4america.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z1HROffCaujv6J6M3Lie2AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-12-05 12:38:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 05 07:38:50.215386 2024] [security2:error] [pid 11398:tid 11425] [client 2a02:1778::113:2c0:51548] [client 2a02:1778::113:2c0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dontbeajerklikeyourwork.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dontbeajerklikeyourwork.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z1Ge2sILMYLCIG17twC5QgAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-12-05 12:13:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:1778::113:2c0 (ipv6.s176.cyber-folks.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 05 07:13:01.841022 2024] [security2:error] [pid 3725057:tid 3725057] [client 2a02:1778::113:2c0:54166] [client 2a02:1778::113:2c0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mainefirst.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mainefirst.org"] [uri "/wp-json/wp/v2/users"] [unique_id "Z1GYzW67PQDfYNEd17kP3QAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-04 23:53:01
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
🇺🇸
mawan
2024-12-03 03:54:36
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
🇦🇺
weblite
2024-11-26 22:00:12
(1 year ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
🇫🇷
Max la Menace
2024-11-22 08:18:56
(1 year ago)
Wordpress Attack (P)
Web App Attack
🇬🇧
Swiptly
2024-11-18 22:36:11
(1 year ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack