|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 06:38:23.817994 2026] [security2:error] [pid 5261:tid 5261] [client 54.189.105.3:55002] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pixelspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pixelspective.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajJ5H2qh4oy730gM4ju1QwAAAAQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 20:25:30.373827 2026] [security2:error] [pid 6648:tid 6648] [client 54.189.105.3:48142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.stop902.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.stop902.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajHpeg0_mnFyNTwZZc08RQAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 10:42:42.435452 2026] [security2:error] [pid 368:tid 368] [client 54.189.105.3:56372] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.thomasgardner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.thomasgardner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajFg4li2yODmeVEisG6YTQAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 09:23:24.353710 2026] [security2:error] [pid 5217:tid 5245] [client 54.189.105.3:48194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.strengthsmatter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.strengthsmatter.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajFOTLRS1dCPmMxHRadKVwAAAZg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
SpaceHost-Server
|
|
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:52:58.192749 2026] [security2:error] [pid 4559:tid 4559] [client 54.189.105.3:37044] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.hawaiireservations.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.hawaiireservations.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai93GilsnzW-Q2IbMdM_EAAAAGg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
SpaceHost-Server
|
|
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ฎ
Rexikon
|
|
54.189.105.3 - - [14/Jun/2026:20:07:37 +0200] "POST /wp-login.php HTTP/1.1" 200 15292 "-" "Mozilla/5 ...
show more
54.189.105.3 - - [14/Jun/2026:20:07:37 +0200] "POST /wp-login.php HTTP/1.1" 200 15292 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:43.0) Gecko/20100101 Firefox/43.0"
54.189.105.3 - - [14/Jun/2026:20:07:56 +0200] "POST /wp-login.php HTTP/1.1" 200 15292 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0"
54.189.105.3 - - [14/Jun/2026:20:07:57 +0200] "POST /wp-login.php HTTP/1.1" 200 15292 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0"
54.189.105.3 - - [14/Jun/2026:20:08:14 +0200] "POST /wp-login.php HTTP/1.1" 200 15292 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0"
54.189.105.3 - - [14/Jun/2026:20:08:22 +0200] "POST /wp-login.php HTTP/1.1" 200 15292 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0"
...
show less
|
Brute-Force
|
|
|
Anonymous
|
|
[redacted] 54.189.105.3 - - [14/Jun/2026:01:29:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 54.189.105.3 - - [14/Jun/2026:01:29:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0"
[redacted] 54.189.105.3 - - [14/Jun/2026:01:29:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:41.0) Gecko/20100101 Firefox/41.0"
[redacted] 54.189.105.3 - - [14/Jun/2026:01:29:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
[redacted] 54.189.105.3 - - [14/Jun/2026:01:29:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0"
[redacted] 54.189.105.3 - - [14/Jun/2026:01:29:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
[redacted] 54.189.105.3 - - [14/Jun/202
...
show less
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 12:13:48.984072 2026] [security2:error] [pid 28106:tid 28106] [client 54.189.105.3:58422] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.investorsfundingusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.investorsfundingusa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai2BvKsZKW6d--V-3lJ0EAAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 54.189.105.3 (ec2-54-189-105-3.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 19:56:15.645591 2026] [security2:error] [pid 29413:tid 29413] [client 54.189.105.3:45314] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.blacksheepoffroad.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ain5n66D3vnZmWXuhWsjdwAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|