๐บ๐ธ
AutoAddOnStore
2026-04-09 17:48:00
(5 months ago)
probing for vulnerabilities
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 14:02:54
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 10:02:49.441288 2026] [security2:error] [pid 712403:tid 712403] [client 51.195.201.179:55449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||3beeze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "3beeze.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "adexiWmjOw9IvENu7_35kQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 13:27:06
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 09:26:58.730299 2026] [security2:error] [pid 3902538:tid 3902538] [client 51.195.201.179:52967] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||36sovereignchambers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "36sovereignchambers.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "adepIrkdJI3Weu1wJYTGxQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-04-09 12:20:04
(5 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 11:50:48
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 07:50:42.826757 2026] [security2:error] [pid 462163:tid 462163] [client 51.195.201.179:65070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.321q.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.321q.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "adeSkmmmTB_FPBH9WEzHNgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-04-09 11:46:28
(5 months ago)
(wordpress) Failed wordpress login from 51.195.201.179 (FR/France/vps-7c09a697.vps.ovh.net)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-09 09:10:41
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 05:10:35.772898 2026] [security2:error] [pid 3499893:tid 3499893] [client 51.195.201.179:51999] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||247.fishing|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "247.fishing"] [uri "/wp-json/wp/v2/users/"] [unique_id "addtC1o2-T78oSAqTfYTTgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-09 09:10:11
(5 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
myagent.site
2026-04-09 08:56:56
(5 months ago)
Blocking for trying to access an exploit file: //xmlrpc.php
Hacking
๐ฎ๐น
VHosting
2026-04-09 08:51:26
(5 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-04-09 08:47:16
(5 months ago)
WordPress: User enumeration. Pattern match "(author\\\\= (1000-123)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 07:38:51
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 03:38:46.082706 2026] [security2:error] [pid 203318:tid 203318] [client 51.195.201.179:49920] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||20dekopas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "20dekopas.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "addXhudVQkyBdmb17kv07gAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-04-09 06:29:18
(5 months ago)
Blocked user enumeration attempt
Hacking
๐ซ๐ฎ
wpwoodo
2026-04-09 06:12:14
(5 months ago)
Webpage crawler
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-09 05:37:33
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 51.195.201.179 (vps-7c09a697.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 01:37:28.592621 2026] [security2:error] [pid 80059:tid 80059] [client 51.195.201.179:53602] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||1954topresent.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "1954topresent.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "adc7GNtTlf5gVorodPCnewAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack