๐บ๐ธ
TPI-Abuse
2026-08-23 16:11:40
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 12:11:31.983637 2026] [security2:error] [pid 6809:tid 6809] [client 62.238.118.71:46350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jtagulator.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jtagulator.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aosbs7KECXN5XQ0neram6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 15:45:05
(1 day ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
Anonymous
2026-08-23 15:07:01
(1 day ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: FI, Attack patterns: Auto ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: FI, Attack patterns: Automated scanning
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:52:28
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:52:25.094361 2026] [security2:error] [pid 11880:tid 11880] [client 62.238.118.71:44430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||peacecampus.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "peacecampus.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aosJKZbSewZW8aHNvPGJhAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-23 14:41:47
(1 day ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.118.71 (FI/Finland/static.71.118.238.62 ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.118.71 (FI/Finland/static.71.118.238.62.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 62.238.118.71 - - [23/Aug/2026:16:41:44 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 1634 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=manzettorosso.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-23 14:34:08
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:34:00.895556 2026] [security2:error] [pid 20079:tid 20079] [client 62.238.118.71:47750] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kentsavagelaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kentsavagelaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aosE2NqEhqE3mGk-c1UtJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
expandmade.com
2026-08-23 13:30:21
(1 day ago)
unauthorized rest api call [23/Aug/2026:13:30:21 "GET /wp-json/wp/v2/users?per_page=100"]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 13:04:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:04:02.355515 2026] [security2:error] [pid 23434:tid 23434] [client 62.238.118.71:52328] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgesmarina.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorvwnjbyyYBGXi73sC9SAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-08-23 12:03:00
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:08:56
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:08:50.680299 2026] [security2:error] [pid 23438:tid 23438] [client 62.238.118.71:36504] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stacyfarm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorUwr7JzKkmu8zx5-DXEAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-23 11:02:03
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-23 11:02 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 08:56:29
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 04:56:24.830025 2026] [security2:error] [pid 11627:tid 11627] [client 62.238.118.71:24844] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bernsteinip.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoq1uFb_3CBNLXXkRLPGcQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 07:41:15
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 03:41:10.125669 2026] [security2:error] [pid 5267:tid 5267] [client 62.238.118.71:48836] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||konahawaiirealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "konahawaiirealty.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoqkFtf5XW4t5BkfxPygeAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 05:14:58
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.118.71 (static.71.118.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:14:51.946219 2026] [security2:error] [pid 21393:tid 21393] [client 62.238.118.71:41814] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brushmileage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brushmileage.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aoqBy2wxLwtSP6QuEnP9wAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-08-23 05:13:12
(2 days ago)
Web App Attack
Web App Attack