🇫🇷
Lunix
2026-08-30 19:34:06
(12 minutes ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 19:12:09
(34 minutes ago)
(mod_security) mod_security (id:225170) triggered by 54.165.218.206 (ec2-54-165-218-206.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 54.165.218.206 (ec2-54-165-218-206.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:12:03.793968 2026] [security2:error] [pid 23565:tid 23565] [client 54.165.218.206:58552] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.silalaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.silalaw.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "apSAg1QPM4rKwkbLRa3LkAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 19:04:47
(42 minutes ago)
Web scanner: GET //wp-includes/wlwmanifest.xml
Web App Attack
Hacking
🇩🇪
thesimonmanuel
2026-08-30 19:04:15
(42 minutes ago)
54.165.218.206 - - [31/Aug/2026:00:34:14 +0530] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 301 5 " ...
show more
54.165.218.206 - - [31/Aug/2026:00:34:14 +0530] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 301 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Web App Attack
🇩🇪
YF
2026-08-30 19:00:17
(46 minutes ago)
WordPress author enumeration
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 18:50:24
(56 minutes ago)
(mod_security) mod_security (id:225170) triggered by 54.165.218.206 (ec2-54-165-218-206.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 54.165.218.206 (ec2-54-165-218-206.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:50:19.357105 2026] [security2:error] [pid 20469:tid 20469] [client 54.165.218.206:62139] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||reallifelearninghub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "reallifelearninghub.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "apR7a65s1AZxXx8Sk2jwywAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 18:33:02
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 54.165.218.206 (ec2-54-165-218-206.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 54.165.218.206 (ec2-54-165-218-206.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:32:55.484854 2026] [security2:error] [pid 3770:tid 3770] [client 54.165.218.206:54329] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||armenianpress.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "armenianpress.am"] [uri "/wp-json/wp/v2/users/"] [unique_id "apR3V2CYGVIIXPaEX40ZJQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-08-30 18:30:36
(1 hour ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇨🇭
zynex
2026-08-30 18:30:27
(1 hour ago)
URL Probing: /wp-includes/wlwmanifest.xml
Web App Attack
🇷🇴
clauss
2026-08-30 18:28:59
(1 hour ago)
54.165.218.206 - - [30/Aug/2026:21:28:47 +0300] "GET //wp-includes/wlwmanifest.xml HTTP/2.0" 404 268 ...
show more
54.165.218.206 - - [30/Aug/2026:21:28:47 +0300] "GET //wp-includes/wlwmanifest.xml HTTP/2.0" 404 2686 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
54.165.218.206 - - [30/Aug/2026:21:28:48 +0300] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 404 2686 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
54.165.218.206 - - [30/Aug/2026:21:28:49 +0300] "GET //web/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
54.165.218.206 - - [30/Aug/2026:21:28:50 +0300] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
54.165.218.206 - - [30/Aug/2026:21:28:51 +0300] "GET //website/wp-includes/wlwmanifest.xml
...
show less
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-08-30 18:25:16
(1 hour ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
Anonymous
2026-08-30 18:23:21
(1 hour ago)
Blocked by ModSec and CSF
Port Scan
🇳🇱
BlueWire Hosting
2026-08-30 18:18:11
(1 hour ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 18:17:50
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 54.165.218.206 (ec2-54-165-218-206.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 54.165.218.206 (ec2-54-165-218-206.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:17:43.224723 2026] [security2:error] [pid 7368:tid 7368] [client 54.165.218.206:56042] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tigerpathteam.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tigerpathteam.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "apRzxzNJPrPAkfIoO467RAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
mgarofano80
2026-08-30 17:53:57
(1 hour ago)
Brute-Force
Web App Attack