🇺🇸
TPI-Abuse
2026-08-29 17:28:13
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 13:28:09.190663 2026] [security2:error] [pid 19380:tid 19380] [client 66.96.183.229:51202] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jillbauman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jillbauman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apMWqdPgFCTisrFtg13H-QAAAAs"], referer: https://jillbauman.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 14:51:34
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 10:51:28.122516 2026] [security2:error] [pid 28175:tid 28175] [client 66.96.183.229:39322] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||karenbernsteinlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "karenbernsteinlaw.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apLx8KvtXAd-wouGPJLhfgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 18:00:40
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:00:33.066177 2026] [security2:error] [pid 7322:tid 7322] [client 66.96.183.229:52394] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doncody.disio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doncody.disio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apHMwW9hITawJpetpJJtfgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 00:56:40
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:56:34.241998 2026] [security2:error] [pid 18543:tid 18602] [client 66.96.183.229:40792] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||supercyprus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "supercyprus.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apDcwothYpSWCkWKRgK8_AAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
www.winos.me
2026-08-28 00:00:46
(1 day ago)
Scanning for sensitive files/paths: /wp-login.php
Hacking
Web App Attack
🇲🇹
Malta
2026-08-27 06:09:12
(2 days ago)
66.96.183.229 - - [27/Aug/2026:08:09:11 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
66.96.183.229 - - [27/Aug/2026:08:09:11 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-08-26 11:11:32
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:11:27.927370 2026] [security2:error] [pid 20303:tid 20303] [client 66.96.183.229:33312] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cmcnow.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cmcnow.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ao7J36wBT0VbsBDF_XLUywAAAAo"], referer: https://cmcnow.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
filstal.org
2026-08-22 10:01:03
(1 week ago)
CrowdSec: crowdsecurity/postfix-non-smtp-command
Email Spam
Hacking
🇺🇸
TPI-Abuse
2026-08-20 15:02:10
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.229 (229.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 11:02:03.922366 2026] [security2:error] [pid 16311:tid 16311] [client 66.96.183.229:50958] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||constructionloansfunding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "constructionloansfunding.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aocW64N37qcAkmNfZkxhSQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-14 00:10:37
(2 weeks ago)
WordPress Brute Force
Hacking
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-08-12 19:11:32
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
lostswordfish.com
2026-08-10 04:12:06
(2 weeks ago)
Wordfence waf block on ncrsol
Web App Attack
🇺🇸
octageeks.com
2026-02-05 05:06:39
(6 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
Anonymous
2026-02-04 15:12:52
(6 months ago)
wordpress-trap
Web App Attack
🇩🇪
LRob
2026-01-12 07:19:59
(7 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack