๐บ๐ธ
TPI-Abuse
2026-08-22 15:52:51
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:52:44.286252 2026] [security2:error] [pid 12854:tid 12854] [client 62.238.119.48:40204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||unitedletter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "unitedletter.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aonFzMlKDqxp1Nd16X-WgQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tr1n
2026-08-22 15:50:04
(3 hours ago)
Triggered Cloudflare WAF (botFight) from FI.
Action: MANAGED_CHALLENGE | ASN: 24940 (Hetzner Online ...
show more
Triggered Cloudflare WAF (botFight) from FI.
Action: MANAGED_CHALLENGE | ASN: 24940 (Hetzner Online GmbH) | Protocol: HTTP/1.1 (GET) | Endpoint: / | Timestamp: 2026-08-22T15:50:04Z | UA: Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-22 13:55:28
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:55:24.812843 2026] [security2:error] [pid 30703:tid 30703] [client 62.238.119.48:22900] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cubbylure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cubbylure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomqTE1JiTauCfCKw73sNgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 11:59:43
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 07:59:35.896993 2026] [security2:error] [pid 32194:tid 32194] [client 62.238.119.48:54570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frenchla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frenchla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomPJ99Rjftf3iRKtunh9QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-22 10:33:32
(8 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 10:26:16
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:26:12.469411 2026] [security2:error] [pid 19308:tid 19308] [client 62.238.119.48:25236] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonegym.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonegym.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aol5RG13D4BMfnDA_Ut1lwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 10:04:17
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:04:10.560346 2026] [security2:error] [pid 31453:tid 31537] [client 62.238.119.48:36358] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theyogicat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theyogicat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aol0GkQlIPNKJv1rqxuQdwAAAwQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-22 09:13:18
(10 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.119.48 (FI/Finland/static.48.119.238.62 ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.119.48 (FI/Finland/static.48.119.238.62.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 62.238.119.48 - - [22/Aug/2026:11:13:16 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 640 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=effegroup.eu
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-22 00:50:17
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 20:50:11.780709 2026] [security2:error] [pid 25681:tid 25681] [client 62.238.119.48:46730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cayman-islands-real-estate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cayman-islands-real-estate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aojyQ0t6p7kXEXZDoR5xPQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-21 21:11:16
(22 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-08-21 20:05:18
(23 hours ago)
Request Overload (134)
Brute-Force
Web App Attack
๐ฉ๐ช
gadix
2026-08-21 18:50:09
(1 day ago)
[21/Aug/2026:18:57:53.323408 +0200] aoiDkcYCezdLbaK2XmJ_YgAAAAE 62.238.119.48 54408 127.0.0.1 7081
[ ...
show more
[21/Aug/2026:18:57:53.323408 +0200] aoiDkcYCezdLbaK2XmJ_YgAAAAE 62.238.119.48 54408 127.0.0.1 7081
[21/Aug/2026:20:01:38.690981 +0200] aoiSgsYCezdLbaK2XmJ_pwAAAAE 62.238.119.48 37322 127.0.0.1 7081
[21/Aug/2026:20:50:08.271097 +0200] aoid4KupfnZ4-vNxwRBQDAAAAAI 62.238.119.48 52262 127.0.0.1 7081
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 18:08:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 14:08:04.779668 2026] [security2:error] [pid 27015:tid 27015] [client 62.238.119.48:58710] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marshdcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marshdcs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoiUBF45syQuyVtzvmYiJQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-21 18:05:05
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 17:00:22
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.you ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.119.48 (static.48.119.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:00:18.658473 2026] [security2:error] [pid 18240:tid 18240] [client 62.238.119.48:29658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kozyramodularhomebuilder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kozyramodularhomebuilder.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoiEIjg9p2GQFvgxGB_4cgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack