๐ซ๐ท
ELYAZ
2026-06-13 15:59:25
(11 minutes ago)
(wordpress) Failed wordpress login from 3.108.158.24 (IN/India/ec2-3-108-158-24.ap-south-1.compute.a ...
show more
(wordpress) Failed wordpress login from 3.108.158.24 (IN/India/ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
lostswordfish.com
2026-06-13 14:20:07
(1 hour ago)
Wordfence waf block on registrymatters
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 14:13:20
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 10:13:17.076600 2026] [security2:error] [pid 11882:tid 11882] [client 3.108.158.24:53934] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||odysseydogasporlari.com.handankoc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "odysseydogasporlari.com.handankoc.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai1lfcsHu8ifQprV255CGQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 08:10:28
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 04:10:23.758048 2026] [security2:error] [pid 18689:tid 18750] [client 3.108.158.24:51318] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mtiminis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mtiminis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai0Qb_a-d81L9rlh_82yPAAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-13 05:08:05
(11 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
iNetWorker
2026-06-13 05:05:31
(11 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
ambor
2026-06-13 04:35:00
(11 hours ago)
Honeypot triggered: /wp-json/learnpress/v1/users on ifebridge.com. User-Agent: Mozilla/5.0 (Windows ...
show more
Honeypot triggered: /wp-json/learnpress/v1/users on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36. Method: GET
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 02:28:14
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 22:28:08.510935 2026] [security2:error] [pid 30721:tid 30721] [client 3.108.158.24:55746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||uccryakima.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "uccryakima.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aizAOHUsiNnfIz38618sOgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 00:54:41
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 20:54:37.409392 2026] [security2:error] [pid 10536:tid 10536] [client 3.108.158.24:37440] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||onlinesuretybonds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "onlinesuretybonds.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiyqTUiTLWg10XxiFbWdjQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-13 00:45:08
(15 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 20:56:48
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 16:56:43.746502 2026] [security2:error] [pid 12902:tid 12902] [client 3.108.158.24:57932] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frenchla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frenchla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aixyi8lMB5icTp5VMp6k1gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 19:39:09
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 15:39:03.761203 2026] [security2:error] [pid 8937:tid 8937] [client 3.108.158.24:43176] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mavikalem.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aixgV0vUB1fbaXXn7tMESQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 18:49:44
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 14:49:41.613027 2026] [security2:error] [pid 22326:tid 22326] [client 3.108.158.24:47714] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgesmarina.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aixUxUylcs0qXCwJbRVJ8QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 18:05:56
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 14:05:49.174419 2026] [security2:error] [pid 9702:tid 9702] [client 3.108.158.24:43746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atmoorehealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atmoorehealthcare.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aixKfY_qXeHz4ubcEtISPAAAAA0"], referer: https://atmoorehealthcare.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 16:41:19
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compu ...
show more
(mod_security) mod_security (id:225170) triggered by 3.108.158.24 (ec2-3-108-158-24.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 12:41:13.663365 2026] [security2:error] [pid 16711:tid 16711] [client 3.108.158.24:40632] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||raintechgutters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "raintechgutters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiw2qelnPeTBih_cEXdhOgAAAAc"], referer: https://raintechgutters.com/
show less
Brute-Force
Bad Web Bot
Web App Attack