๐บ๐ธ
TPI-Abuse
2026-05-18 23:07:23
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 19:07:19.975884 2026] [security2:error] [pid 28455:tid 28455] [client 5.39.85.122:49302] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cmcnow.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cmcnow.net"] [uri "/wp-json/wp/v2/users"] [unique_id "agubpy3mIeDOeCB69SX7CgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-18 06:09:19
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 02:09:11.814096 2026] [security2:error] [pid 13038:tid 13038] [client 5.39.85.122:47690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.stationrestaurant.ca|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.stationrestaurant.ca"] [uri "/wp-json/wp/v2/users"] [unique_id "agqtB54MpHh08nmInpS5qQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 18:43:23
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 14:43:18.588748 2026] [security2:error] [pid 21000:tid 21000] [client 5.39.85.122:42570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.forerunnersjazz.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.forerunnersjazz.org"] [uri "/wp-json/wp/v2/users"] [unique_id "agoMRnG5Ui50zgJYStJl9gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 08:12:47
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 04:12:40.241107 2026] [security2:error] [pid 23624:tid 23624] [client 5.39.85.122:36584] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "celebritybikinigossip.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agl4eCZA6FbQLLTZ3MMrlwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-05-17 07:48:36
(4 months ago)
Blocked by CSF 13 firewall - Rule: FR/France/vfx2.guiaescolar.net
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 04:05:52
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 00:05:46.044993 2026] [security2:error] [pid 27618:tid 27618] [client 5.39.85.122:53156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.hsoftwaresystems.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.hsoftwaresystems.net"] [uri "/wp-json/wp/v2/users"] [unique_id "agk-miuMSvMy8fDe0HSyvwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 18:53:20
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 5.39.85.122 (vfx2.guiaescolar.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 14:53:15.866523 2026] [security2:error] [pid 26226:tid 26226] [client 5.39.85.122:58276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agi9G85WN-NBcJTC2xo5aAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-16 02:56:28
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฒ๐น
Malta
2026-03-11 23:40:09
(6 months ago)
5.39.85.122 - - [12/Mar/2026:00:40:09 +0100] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10 ...
show more
5.39.85.122 - - [12/Mar/2026:00:40:09 +0100] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:46.0) Gecko/20100101 Firefox/46.0"
show less
Hacking
Web App Attack
๐ธ๐ฎ
borisperc
2025-08-03 10:51:51
(1 year ago)
Web Spam
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2025-01-23 05:15:07
(1 year ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-01-23 02:36:46
(1 year ago)
(WPLOGIN) WP Login Attack 5.39.85.122 (vfx2.guiaescolar.net): 5 in the last 3600 secs; Ports: *; Dir ...
show more
(WPLOGIN) WP Login Attack 5.39.85.122 (vfx2.guiaescolar.net): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
Joey_B
2025-01-23 01:42:00
(1 year ago)
wp-login attack
DDoS Attack
Web App Attack
๐ฉ๐ช
Joey_B
2025-01-22 23:06:00
(1 year ago)
wp-login attack
DDoS Attack
Web App Attack
Anonymous
2025-01-22 22:31:08
(1 year ago)
apache-wordpress-login
Brute-Force
Web App Attack