๐บ๐ธ
TPI-Abuse
2026-05-12 08:52:37
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 04:52:30.970222 2026] [security2:error] [pid 2269:tid 2269] [client 49.13.171.11:36264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frenchla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frenchla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLqTiHMNL9WLJLnZ3ToDgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sverson
2026-05-12 08:19:20
(3 weeks ago)
Trolling for resource vulnerabilities / Unauthorized login attempts / Wordpress Attack Attempt
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-12 08:05:59
(3 weeks ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ฉ๐ช
stinpriza
2026-05-12 07:21:45
(3 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 07:21:44
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 03:21:38.548376 2026] [security2:error] [pid 28439:tid 28439] [client 49.13.171.11:37984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonnesfrequences.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonnesfrequences.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLVAuJNclDehEiiloVv4gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 07:04:09
(3 weeks ago)
2026-05-12T09:04:08.857904+02:00 aion wordpress[1691897]: Blocked user enumeration attempt from 49.1 ...
show more
2026-05-12T09:04:08.857904+02:00 aion wordpress[1691897]: Blocked user enumeration attempt from 49.13.171.11
...
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-12 06:52:54
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 02:52:47.883416 2026] [security2:error] [pid 5203:tid 5203] [client 49.13.171.11:44188] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||xcarsubscription.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "xcarsubscription.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLOP5cLzhZXniH8dTJxEQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-12 06:44:55
(3 weeks ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 06:22:18
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 02:22:15.534286 2026] [security2:error] [pid 9141:tid 9141] [client 49.13.171.11:40420] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dalessalesandservice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dalessalesandservice.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLHF-q38Cq7fa3UN5lMGQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-05-12 06:03:59
(3 weeks ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 06:02:52
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 02:02:42.874388 2026] [security2:error] [pid 29502:tid 29553] [client 49.13.171.11:43002] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||teddysdeli.omegaoak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "teddysdeli.omegaoak.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agLCgp8aVOHA0sXDy78M9wAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 05:25:47
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 01:25:43.046373 2026] [security2:error] [pid 17876:tid 17876] [client 49.13.171.11:49910] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||josephshv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "josephshv.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agK511-dq1SDHAWd4YIRaAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
plzenskypruvodce.cz
2026-05-12 05:09:00
(3 weeks ago)
2026-05-12T07:08:59.450158+02:00 web wordpress(varhanykolin.cz)[2559470]: Immediately block connecti ...
show more
2026-05-12T07:08:59.450158+02:00 web wordpress(varhanykolin.cz)[2559470]: Immediately block connections from 49.13.171.11
...
show less
Brute-Force
๐ง๐ช
cmbplf
2026-05-12 05:01:00
(3 weeks ago)
11.411 requests in 1 hour (2mos3w3d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-12 04:56:59
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 49.13.171.11 (srv1.denm.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 00:56:55.140453 2026] [security2:error] [pid 16711:tid 16711] [client 49.13.171.11:58532] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||staben.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "staben.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agKzF0QT9UWqvK1cdgd0vQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack