๐บ๐ธ
TPI-Abuse
2026-08-28 17:10:33
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:10:28.962115 2026] [security2:error] [pid 12129:tid 12129] [client 51.38.30.221:59000] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lysedzija.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apHBBPoe0O-G9vSCXTHVUQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-27 00:31:46
(2 days ago)
(wordpress) Failed wordpress login from 51.38.30.221 (FR/France/-/-/gharsha.tasjeel.ae/[redacted]): ...
show more
(wordpress) Failed wordpress login from 51.38.30.221 (FR/France/-/-/gharsha.tasjeel.ae/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
cwytech
2026-08-26 16:32:03
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 07:53:41
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:53:37.933217 2026] [security2:error] [pid 20864:tid 20864] [client 51.38.30.221:40124] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.webseographics.smogsandiego.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.webseographics.smogsandiego.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6bgR5RBoStSyv2LAkbpAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 07:26:44
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:26:36.142148 2026] [security2:error] [pid 6486:tid 6486] [client 51.38.30.221:42378] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bigheartskitchen.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bigheartskitchen.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6VLCWksGCapiRErEwmAgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-31 04:21:46
(4 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ญ๐บ
bcsaba
2026-07-31 01:43:37
(4 weeks ago)
CMS (WordPress or Joomla) login attempt.
51.38.30.221 - - [31/Jul/2026:03:43:36 +0200] "POST /wp-log ...
show more
CMS (WordPress or Joomla) login attempt.
51.38.30.221 - - [31/Jul/2026:03:43:36 +0200] "POST /wp-login.php HTTP/2.0" 200 4009 "https://*REDACTED*/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
๐ฆ๐บ
MAGIC
2026-06-12 02:22:44
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
octageeks.com
2026-05-17 04:07:42
(3 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-17 02:55:26
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
Hazzard
2026-05-16 09:50:12
(3 months ago)
(wordpress) Failed wordpress login from 51.38.30.221 (FR/France/-/-/gharsha.tasjeel.ae/[redacted]): ...
show more
(wordpress) Failed wordpress login from 51.38.30.221 (FR/France/-/-/gharsha.tasjeel.ae/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐ฒ๐น
Malta
2026-05-15 18:57:19
(3 months ago)
51.38.30.221 - - [15/May/2026:20:57:19 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
51.38.30.221 - - [15/May/2026:20:57:19 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-15 03:35:19
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 23:35:16.178307 2026] [security2:error] [pid 30690:tid 30690] [client 51.38.30.221:51034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||n4fh.cosentient.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "n4fh.cosentient.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agaUdKvi9ApaxGS8F3nm3AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 05:42:36
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 01:42:32.820444 2026] [security2:error] [pid 3150:tid 3165] [client 51.38.30.221:54094] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jofdt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jofdt.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agVgyKidPApMqs5ssZiJOgAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 18:10:35
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 51.38.30.221 (gharsha.tasjeel.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 14:10:28.416446 2026] [security2:error] [pid 19789:tid 19789] [client 51.38.30.221:34918] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aroilcontrolsystem.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aroilcontrolsystem.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agS-lBIU0jlUXPyKQXqf9QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack