๐ฉ๐ช
neckaralb-admin.de
2026-07-28 12:29:01
(53 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-28 04:11:14
(9 hours ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 02:18:56
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 22:18:50.613596 2026] [security2:error] [pid 198861:tid 198861] [client 59.110.115.107:60070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rodzillacharters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rodzillacharters.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "amgRiiQcNmJ3i_y5NM8uygAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 01:56:41
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 21:56:37.349221 2026] [security2:error] [pid 183072:tid 183072] [client 59.110.115.107:33332] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jasonmcquain.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jasonmcquain.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amgMVWUfA_h_97-8Gr6_gQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 21:46:56
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 17:46:49.784578 2026] [security2:error] [pid 3536996:tid 3537017] [client 59.110.115.107:33062] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iancaird.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iancaird.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amfRyX9NukUPDGjP-WDtzgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 18:42:58
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:42:52.622449 2026] [security2:error] [pid 464155:tid 464155] [client 59.110.115.107:44678] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eatcakecup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eatcakecup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amemrAPy7Mj5NursT4--NAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-27 17:35:14
(19 hours ago)
dance4fitness.com.au:443 59.110.115.107 - - [28/Jul/2026:03:35:11 +1000] "GET /?author=1 HTTP/1.1" 4 ...
show more
dance4fitness.com.au:443 59.110.115.107 - - [28/Jul/2026:03:35:11 +1000] "GET /?author=1 HTTP/1.1" 404 174534 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 17:00:49
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:00:44.867771 2026] [security2:error] [pid 4010431:tid 4010431] [client 59.110.115.107:49942] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webuychesterfieldhouses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webuychesterfieldhouses.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ameOvBrF_eFGWp5hZxImvQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:27:31
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:27:23.723780 2026] [security2:error] [pid 869249:tid 869249] [client 59.110.115.107:49280] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leolion.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leolion.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amd425ZymZUB4IBIo9-48AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 03:39:59
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 23:39:54.987925 2026] [security2:error] [pid 790259:tid 790259] [client 59.110.115.107:38904] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eduempowermentsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eduempowermentsolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amA7ijWERvfJmg5LT2xTowAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-22 02:47:27
(6 days ago)
indigi-print-merch.com.au:443 59.110.115.107 - - [22/Jul/2026:12:47:25 +1000] "GET /?author=1 HTTP/1 ...
show more
indigi-print-merch.com.au:443 59.110.115.107 - - [22/Jul/2026:12:47:25 +1000] "GET /?author=1 HTTP/1.1" 404 313408 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 00:58:25
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 20:58:17.827437 2026] [security2:error] [pid 120752:tid 120752] [client 59.110.115.107:38018] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inverzona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inverzona.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "amAVqb8dlOS5ERMl9HWKHgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
boxed-it
2026-06-24 11:57:04
(1 month ago)
GET /wp-login.php (Tarpitted for 1d15h8m29s, wasted 8.06MB)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-23 22:00:48
(1 month ago)
Auto-ban: >3000 req/min op 2026-06-23
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-23 08:03:31
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 59.110.115.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 04:03:26.244573 2026] [security2:error] [pid 29120:tid 29120] [client 59.110.115.107:34516] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||holgerfeld.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "holgerfeld.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "ajo9zq-YL728uZX6J1GddwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack