🇺🇸
TPI-Abuse
2026-09-09 04:59:57
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): ...
show more
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:59:50.665334 2026] [security2:error] [pid 31549:tid 31549] [client 78.63.103.198:57912] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theaccents.mainstreetofficesuites.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theaccents.mainstreetofficesuites.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDnxigrBKw-b5TN8x0zKwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-09 03:33:29
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇫🇷
masterguru
2026-09-09 02:29:29
(4 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 78.63.103.198 (LT/Lithuania/78-63-103-198.sta ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 78.63.103.198 (LT/Lithuania/78-63-103-198.static.zebra.lt): 1 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
cwytech
2026-09-09 01:36:31
(5 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:28:21
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): ...
show more
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:28:15.881250 2026] [security2:error] [pid 14037:tid 14037] [client 78.63.103.198:36262] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newcastle91.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newcastle91.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC2L7ACakinfZHr1H63WQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:54:49
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): ...
show more
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:54:43.664788 2026] [security2:error] [pid 4480:tid 4480] [client 78.63.103.198:41662] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grandpont-house.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grandpont-house.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqB2E5eK57C0d1ntKrQeUwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:55:20
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): ...
show more
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:55:12.675146 2026] [security2:error] [pid 17319:tid 17319] [client 78.63.103.198:46386] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "schlegelcreative.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBoIOzgqeexF0grILQwvwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-08 18:16:22
(12 hours ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 198.103.63.78.rbl.malwa ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 198.103.63.78.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-08 17:23:08
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): ...
show more
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:23:03.571850 2026] [security2:error] [pid 16859:tid 16859] [client 78.63.103.198:58252] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||usaenquirer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "usaenquirer.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBEd1EPmWapIKD-AqzXoQAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Lino Project
2026-09-08 15:27:11
(15 hours ago)
78.63.103.198 - - [08/Sep/2026:17:27:10 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 ...
show more
78.63.103.198 - - [08/Sep/2026:17:27:10 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:34:10
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): ...
show more
(mod_security) mod_security (id:225170) triggered by 78.63.103.198 (78-63-103-198.static.zebra.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:34:05.079045 2026] [security2:error] [pid 1796039:tid 1796070] [client 78.63.103.198:40816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ward-bergerhouse.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ward-bergerhouse.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_yrXLu7iCm5PR--fPVLQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 10:28:36
(20 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-08 08:07:57
(22 hours ago)
WordPress login attempt
Brute-Force
🇲🇽
octageeks.com
2026-09-08 04:13:53
(1 day ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇺🇸
RAP
2026-01-08 01:12:36
(8 months ago)
2026-01-08 01:12:36 UTC Unauthorized activity to TCP port 2323. Telnet
Port Scan