🇺🇸
TPI-Abuse
2026-08-31 02:20:04
(17 minutes ago)
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 22:19:55.272806 2026] [security2:error] [pid 25305:tid 25305] [client 68.183.64.6:47716] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonesband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonesband.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apTky6DqVAZR8nTGQBUhEgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 01:52:46
(45 minutes ago)
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 21:52:42.256507 2026] [security2:error] [pid 4150:tid 4150] [client 68.183.64.6:47624] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||f40ph.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "f40ph.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apTeaqjCPP4IdgF-pvSeHQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
joe-abuse
2026-08-31 01:47:51
(49 minutes ago)
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 1 ...
show more
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 19:30:17. Events: 1. Reported by ipdb-security/fitzgerald.eu
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 00:56:37
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 20:56:30.695881 2026] [security2:error] [pid 19014:tid 19033] [client 68.183.64.6:33726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wnsi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wnsi.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apTRPhIc2WyLuqS2zm8eUQAAABE"], referer: http://wnsi.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
SilverZippo
2026-08-31 00:55:35
(1 hour ago)
Web App Attack
Web App Attack
🇩🇪
eposs-it.de
2026-08-31 00:50:12
(1 hour ago)
Blocked by os-abuseipdb; 12 hits, proto=tcp, ports=443,80
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-08-31 00:35:10
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 20:35:04.381878 2026] [security2:error] [pid 18420:tid 18420] [client 68.183.64.6:42458] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pathpa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pathpa.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apTMOBft9uwZmvCahzpWNwAAAAQ"], referer: http://pathpa.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
LRob
2026-08-30 23:10:50
(3 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-30 23:10 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 23:08:24
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 19:08:16.228357 2026] [security2:error] [pid 11167:tid 11167] [client 68.183.64.6:46980] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||meganmurph.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "meganmurph.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apS34DhNHMWqB0xE5YTr-AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-30 22:56:11
(3 hours ago)
Web vulnerability probing: /wp-login.php (bogus vhost/SNI)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 22:41:51
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 68.183.64.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 18:41:44.922181 2026] [security2:error] [pid 17488:tid 17488] [client 68.183.64.6:50938] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "major33.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apSxqIGDD78w4t2ZxfnMjQAAAAE"], referer: http://major33.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-30 22:34:35
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-30 22:15:04
(4 hours ago)
Bot / scanning and/or hacking attempts: [1/1] done, GET /wp-login.php HTTP/2.0, GET /wp-login.php HT ...
show more
Bot / scanning and/or hacking attempts: [1/1] done, GET /wp-login.php HTTP/2.0, GET /wp-login.php HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
ambor
2026-08-30 22:14:12
(4 hours ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
🇩🇪
DocNetzwerk
2026-08-30 22:11:26
(4 hours ago)
(wordpress) Failed wordpress login from 68.183.64.6 (DE/Germany/-)
Brute-Force