๐บ๐ธ
TPI-Abuse
2026-06-30 04:52:19
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 00:52:11.935226 2026] [security2:error] [pid 4214:tid 4214] [client 41.185.8.245:39370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jeanniemorrislaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jeanniemorrislaw.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akNLe4_vok9SdQPbx0kX4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-06-29 23:02:09
(17 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-06-29 16:11:00
(1 day ago)
41.185.8.245 - - [29/Jun/2026:18:11:00 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
41.185.8.245 - - [29/Jun/2026:18:11:00 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
Anonymous
2026-06-29 16:09:55
(1 day ago)
WordPress Brute Force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-29 08:38:44
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 04:38:40.079104 2026] [security2:error] [pid 6543:tid 6543] [client 41.185.8.245:39816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jimrichardart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jimrichardart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akIvENHxxWY1le3VSRNvHAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-29 08:06:33
(1 day ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 07:35:24
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 03:35:17.519338 2026] [security2:error] [pid 12345:tid 12345] [client 41.185.8.245:39514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brainstormer.soy|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brainstormer.soy"] [uri "/wp-json/wp/v2/users"] [unique_id "akIgNeoXyWGqJbe6zrg0XQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-29 03:55:35
(1 day ago)
Try to access /de-ideale-stookmix//blog/xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 02:41:32
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 22:41:24.319925 2026] [security2:error] [pid 19174:tid 19174] [client 41.185.8.245:51098] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||plazahacienda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "plazahacienda.com"] [uri "/wp-json/wp/v2/users/4"] [unique_id "akHbVBIcyqjJeSZ18IMjWQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 23:48:27
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 19:48:21.277541 2026] [security2:error] [pid 22322:tid 22322] [client 41.185.8.245:54996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tigerpathteam.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tigerpathteam.org"] [uri "/wp-json/wp/v2/users/8"] [unique_id "akGyxT0gA2B8_m81gsDhZgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 21:47:42
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 17:47:37.884706 2026] [security2:error] [pid 28683:tid 28683] [client 41.185.8.245:35388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||navarrete.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "navarrete.ws"] [uri "/wp-json/wp/v2/users"] [unique_id "akGWebZn-djpUNM_cahASwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 20:14:14
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 16:14:11.081364 2026] [security2:error] [pid 22590:tid 22614] [client 41.185.8.245:45818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jpdesign.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jpdesign.us"] [uri "/wp-json/wp/v2/users/6"] [unique_id "akGAk5M8yfdlhmxvK_ZlWAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 19:19:56
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 15:19:47.661962 2026] [security2:error] [pid 16450:tid 16450] [client 41.185.8.245:43316] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||climasyequipos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "climasyequipos.com"] [uri "/wp-json/wp/v2/users/3"] [unique_id "akFz0-DDPuNS5a1GxjKEogAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-28 14:02:34
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 12:53:44
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.245 (srv52.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 08:53:38.522248 2026] [security2:error] [pid 19082:tid 19087] [client 41.185.8.245:43130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosureinternetservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosureinternetservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akEZUiVAXDI2N_XS0sxYKgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack