🇺🇸
TPI-Abuse
2026-08-11 09:26:07
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 05:25:54.557542 2026] [security2:error] [pid 3965272:tid 3965272] [client 64.49.38.48:64327] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chapa.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chapa.net"] [uri "/wp-json/wp/v2/users"] [unique_id "anrqopq_VYvgQFEbQav7lAAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 20:08:07
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 16:07:54.532014 2026] [security2:error] [pid 2013572:tid 2013615] [client 64.49.38.48:55937] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flapjacktoys.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flapjacktoys.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anJGmi0pn9-0rtISq6E1SgAAAEM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 14:21:31
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 10:21:24.782875 2026] [security2:error] [pid 1431935:tid 1431935] [client 64.49.38.48:38175] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lietzau.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lietzau.net"] [uri "/wp-json/wp/v2/users"] [unique_id "anCj5D_GGg05qMh9-Lu5JgAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-06-16 11:45:05
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-06-11 11:44:40
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-44.64.49.38.48.web-spammers ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-44.64.49.38.48.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-05-22 14:01:53
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 10:01:43.924976 2026] [security2:error] [pid 17756:tid 17756] [client 64.49.38.48:61569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grexicon.com"] [uri "/.wp-config.php.swp"] [unique_id "ahBhx7K8F8D8F9PDBxNvaQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
sshtmp
2026-05-22 12:38:13
(3 months ago)
[AbuseIPDB auto-report]
Attack: WordPress XML-RPC brute-force
Hits: 2 | First: 2026-05-21T18:29:29+0 ...
show more
[AbuseIPDB auto-report]
Attack: WordPress XML-RPC brute-force
Hits: 2 | First: 2026-05-21T18:29:29+02:00 | Last: 2026-05-22T14:38:13+02:00
Samples: POST /xmlrpc.php [200]
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-22 00:22:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 20:22:31.569737 2026] [security2:error] [pid 21655:tid 21655] [client 64.49.38.48:25751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vrevgaming.net"] [uri "/wp-config.php.bak"] [unique_id "ag-hxyfy8qG8vMQUCxnDXQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 19:24:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 15:24:35.283800 2026] [security2:error] [pid 19712:tid 19712] [client 64.49.38.48:27917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batesstrategygroup.com"] [uri "/wp-config.php.dist"] [unique_id "ag4Kc_3Dk8atpgAy6cMsTgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 17:47:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 13:47:40.301224 2026] [security2:error] [pid 6813:tid 6813] [client 64.49.38.48:31733] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.partners.imagineyourphotos.com"] [uri "/wp-config.php.save"] [unique_id "ag3zvGLfP_fUM2e9Z-KMeQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 16:49:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:49:50.488328 2026] [security2:error] [pid 15536:tid 15552] [client 64.49.38.48:10175] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.noharm-nofowl.plumeraproductions.com"] [uri "/wp-config.php.orig"] [unique_id "ag3mLjEqR1DVDZmczhCCzQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 12:43:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 64.49.38.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:43:48.163172 2026] [security2:error] [pid 12249:tid 12249] [client 64.49.38.48:39049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ceren.kircali.net"] [uri "/wp-config.php~"] [unique_id "ag2shOVbdyYvH2BmeajATgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-05-16 09:15:06
(3 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
🇩🇪
dispaisyenterprises
2026-05-15 03:21:52
(3 months ago)
Honeypot [fra-de-honeypot]: Unauthorized traffic (230 bytes of payload); 8089 [2] TCP
Reported by Di ...
show more
Honeypot [fra-de-honeypot]: Unauthorized traffic (230 bytes of payload); 8089 [2] TCP
Reported by DisPaisy Enterprises (dispaisy.systems) using: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Port Scan
Anonymous
2026-04-30 03:00:42
(4 months ago)
Forum/form spam
Web Spam