🇺🇸
TPI-Abuse
2026-09-05 02:05:23
(45 minutes ago)
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:05:16.266075 2026] [security2:error] [pid 6714:tid 6714] [client 5.196.194.156:7412] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mjkhan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mjkhan.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apt43E_eXswvxM40Wg51OQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
abuseiphack
2026-09-05 01:38:26
(1 hour ago)
Automatic report for brute force attack
Web App Attack
🇧🇪
taivas.nl
2026-09-05 01:32:13
(1 hour ago)
Bad_requests
Bad Web Bot
Anonymous
2026-09-05 01:20:04
(1 hour ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-05 01:06:24
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:06:20.897496 2026] [security2:error] [pid 15728:tid 15728] [client 5.196.194.156:56606] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tgaguide.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tgaguide.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aptrDPmCO44JvJhrAyK5qwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 00:35:05
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:34:58.420132 2026] [security2:error] [pid 2005:tid 2005] [client 5.196.194.156:9612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clipper1970.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clipper1970.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aptjsjrg6rBHFK-9PNPQTgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-05 00:24:03
(2 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-05 00:24 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-05 00:23:37
(2 hours ago)
2026-09-05T00:23:37.206441+00:00 instance-20260804-1025 wordpress(trademarks4all.com)[1625091]: Imme ...
show more
2026-09-05T00:23:37.206441+00:00 instance-20260804-1025 wordpress(trademarks4all.com)[1625091]: Immediately block connections from 5.196.194.156
...
show less
Web App Attack
🇮🇩
xveil
2026-09-05 00:07:23
(2 hours ago)
2026-09-05T07:07:20.050045 mail-honeypot postfix/submission/smtpd[32304]: warning: ip156.ip-5-196-19 ...
show more
2026-09-05T07:07:20.050045 mail-honeypot postfix/submission/smtpd[32304]: warning: ip156.ip-5-196-194.eu[5.196.194.156]: SASL PLAIN authentication failed: authentication failure
...
show less
Brute-Force
🇫🇮
danskefilm.dk
2026-09-05 00:00:01
(2 hours ago)
IMAP password guessing
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 23:57:06
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 19:57:02.032749 2026] [security2:error] [pid 26307:tid 26307] [client 5.196.194.156:17264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||astglobaltech.com.greenlight.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "astglobaltech.com.greenlight.us"] [uri "/wp-json/wp/v2/users"] [unique_id "aptazr0lXNTej1qQ_jmOyAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 23:41:23
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 19:41:19.712944 2026] [security2:error] [pid 2591:tid 2591] [client 5.196.194.156:62458] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rentkase.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rentkase.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aptXH1kUVYkKv8KbJxhVMQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
xxkodedxx
2026-09-04 23:27:07
(3 hours ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
Origin: CZ / AS16276 OVH SAS
Active: 23:25:42→23:26:20 UTC
Volume: 2 HTTP req, 1 honeypot probe(s)
Bait taken: /wp-json/oembed/1.0/embed?url=https%3A%2F%2Fsecond-opinion.zvxlabs.com&format=json
Status mix: 302×1 200×1
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:43:45
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 5.196.194.156 (ip156.ip-5-196-194.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:43:38.384436 2026] [security2:error] [pid 25053:tid 25053] [client 5.196.194.156:31526] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mainefirst.arsenaultartistmanagement.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mainefirst.arsenaultartistmanagement.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aptJmgXMv0STsOSTYkL70QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇮
administrator
2026-09-04 22:34:44
(4 hours ago)
2026-09-04 15:17:35,381 fail2ban.actions [1191]: NOTICE [webadmin-badips] Ban 5.196.194.156
...
show more
2026-09-04 15:17:35,381 fail2ban.actions [1191]: NOTICE [webadmin-badips] Ban 5.196.194.156
2026-09-04 16:42:56,957 fail2ban.actions [1191]: NOTICE [webadmin-nfw] Ban 5.196.194.156
2026-09-04 15:17:35,381 fail2ban.actions [1191]: NOTICE [webadmin-badips] Ban 5.196.194.156
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack