๐บ๐ธ
nationaleventpros.com
2026-09-03 03:05:47
(11 minutes ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-21 04:33:48
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 00:33:43.479564 2026] [security2:error] [pid 14475:tid 14475] [client 77.243.91.70:27667] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||churchtop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "churchtop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aofVJxR5NHffmgcLVHkoVgAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 21:18:55
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 17:18:47.938001 2026] [security2:error] [pid 8614:tid 8702] [client 77.243.91.70:22973] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jefftappan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jefftappan.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoTMN7ro83-MPgyh4piQXgAAAog"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 22:18:03
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 18:17:56.974771 2026] [security2:error] [pid 2260185:tid 2260185] [client 77.243.91.70:44251] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prodigyventure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prodigyventure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anzxFMc3rXV9VA5UIvZnbgAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-03 21:21:09
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 17:21:02.029659 2026] [security2:error] [pid 14086:tid 14086] [client 77.243.91.70:65471] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jordanware.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jordanware.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anEGPnZBFOAsZwL3_IRviQAAACs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-14 05:57:03
(1 month ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
nyt
2026-07-09 09:27:10
(1 month ago)
XMLRPC Attack, WP User Enumeration, WP Author Enumeration
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 18:15:56
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 14:15:51.976492 2026] [security2:error] [pid 26042:tid 26042] [client 77.243.91.70:17093] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thestardance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thestardance.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akqfV3L09hjjIbAucVuzagAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-05 04:07:39
(1 month ago)
WP Armour Plugin detection
Web Spam
Brute-Force
๐ซ๐ท
Tilellit.PRO
2026-06-29 14:01:24
(2 months ago)
Fail2Ban banned 77.243.91.70 for security violations in jail wp-armour. Log: 2026/06/29 14:01:23 [er ...
show more
Fail2Ban banned 77.243.91.70 for security violations in jail wp-armour. Log: 2026/06/29 14:01:23 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 77.243.91.70 | Target: wplogin" , client: 77.243.91.70, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-28 08:47:27
(2 months ago)
Fail2Ban banned 77.243.91.70 for security violations in jail wp-armour. Log: 2026/06/28 08:47:26 [er ...
show more
Fail2Ban banned 77.243.91.70 for security violations in jail wp-armour. Log: 2026/06/28 08:47:26 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 77.243.91.70 | Target: wplogin" , client: 77.243.91.70, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-27 05:47:00
(2 months ago)
Fail2Ban banned 77.243.91.70 for security violations in jail wp-armour. Log: 2026/06/27 05:47:00 [er ...
show more
Fail2Ban banned 77.243.91.70 for security violations in jail wp-armour. Log: 2026/06/27 05:47:00 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 77.243.91.70 | Target: wplogin" , client: 77.243.91.70, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Campus France
2026-06-22 06:28:36
(2 months ago)
[Mon Jun 22 08:28:30.051879 2026] [php:error] [pid 3301377] [client 77.243.91.70:43313] script '/var ...
show more
[Mon Jun 22 08:28:30.051879 2026] [php:error] [pid 3301377] [client 77.243.91.70:43313] script '/var/www/html/brume.org/xmlrpc.php' not found or unable to stat
[Mon Jun 22 08:28:35.994999 2026] [php:error] [pid 3301584] [client 77.243.91.70:62377] script '/var/www/html/brume.org/wp-login.php' not found or unable to stat, referer: https://www.google.com
[Mon Jun 22 08:28:36.078971 2026] [php:error] [pid 3298872] [client 77.243.91.70:57407] script '/var/www/html/brume.org/wp-login.php' not found or unable to stat, referer: https://www.google.com
[Mon Jun 22 08:28:36.130878 2026] [php:error] [pid 3300636] [client 77.243.91.70:47059] script '/var/www/html/brume.org/wp-admin.php' not found or unable to stat, referer: https://www.google.com
[Mon Jun 22 08:28:36.285752 2026] [php:error] [pid 3300280] [client 77.243.91.70:50979] script '/var/www/html/brume.org/xmlrpc.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-10 04:28:12
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.243.91.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 00:28:05.900560 2026] [security2:error] [pid 2012969:tid 2012993] [client 77.243.91.70:59461] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||richardleeweatherman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "richardleeweatherman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adh8VTWFVh4E9si09Z0lQgAAANI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-04 19:29:48
(4 months ago)
"GET /wp-login.php HTTP/1.1"
Hacking
Web App Attack