🇸🇪
OnTheEdge
2026-09-09 13:30:33
(22 hours ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
Anonymous
2026-07-27 01:25:10
(1 month ago)
XMLRPC BRUTEFORCE - HTTP (Request)
Hacking
🇺🇸
TPI-Abuse
2026-07-19 11:37:05
(1 month ago)
(mod_security) mod_security (id:218580) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:218580) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 07:37:01.093102 2026] [security2:error] [pid 1228:tid 1228] [client 31.134.3.173:43739] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:codigo. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||www.clubfansite.com.creartest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "www.clubfansite.com.creartest.com"] [uri "/apuntarse.php"] [unique_id "aly23VIYCR9vU5lxKQfE1QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 01:17:04
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 21:16:57.077167 2026] [security2:error] [pid 10600:tid 10600] [client 31.134.3.173:26665] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||guarinofurnituredesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "guarinofurnituredesigns.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akcNiQDY8Bn54HKZMjvvVwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-02 10:34:12
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 06:34:07.671752 2026] [security2:error] [pid 17082:tid 17082] [client 31.134.3.173:65505] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tedharris.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akY-nyDoym-O9GYXZLGC5AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-02-28 12:47:51
(6 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇺🇸
TPI-Abuse
2026-02-21 08:23:09
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 03:23:05.583683 2026] [security2:error] [pid 18825:tid 18825] [client 31.134.3.173:20167] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||buenasfrecuencias.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "buenasfrecuencias.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZlrad1uGeyzviwXscUeQwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-21 03:41:00
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 22:40:55.846289 2026] [security2:error] [pid 363:tid 363] [client 31.134.3.173:53255] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||riser-astrology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "riser-astrology.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZkpR61Nukn0lzPcyRlvzAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-21 01:36:10
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.3.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 20:36:06.743149 2026] [security2:error] [pid 24713:tid 24713] [client 31.134.3.173:12897] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aimer.es|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aimer.es"] [uri "/wp-json/wp/v2/users"] [unique_id "aZkMBrYsvQM7pVDc7RYRPgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
fbarela
2026-02-12 21:00:16
(6 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-11-03 08:05:00
(10 months ago)
"Security violation, excess traffic against library/education infrastructure"
Brute-Force