🇫🇷
Phenix Info
2026-08-30 06:49:12
(18 hours ago)
SmallGuard.fr/Prestashop Massive 403
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 01:53:17
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:53:11.963202 2026] [security2:error] [pid 13222:tid 13238] [client 83.142.55.89:43183] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aafm.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aafm.org"] [uri "/http/charteredfinancialmanager.com"] [unique_id "aoJph9DTcaQUSMFR9lxSLAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-06-11 17:57:45
(2 months ago)
Web password guessing
Brute-Force
🇺🇸
TPI-Abuse
2026-05-28 06:31:05
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 02:30:59.822421 2026] [security2:error] [pid 30408:tid 30408] [client 83.142.55.89:47585] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wisewerks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wisewerks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahfhI6yvoWHTZI0N5Fh6nQAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
on-com
2026-03-25 01:25:25
(5 months ago)
URL scan
Brute-Force
Web App Attack
🇩🇪
LRob
2026-03-24 21:45:02
(5 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-23 11:50:20
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 07:49:40.596193 2026] [security2:error] [pid 16058:tid 16058] [client 83.142.55.89:18409] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ejnes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ejnes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acEo1JpADAg80MFnzBCrfQAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-22 22:45:18
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 18:45:12.801747 2026] [security2:error] [pid 14639:tid 14639] [client 83.142.55.89:55149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodpage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodpage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acBw-MpEWOAf0_rQ1DEy9wAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-03-22 01:56:12
(5 months ago)
WordPress login attempt
Brute-Force
🇩🇪
stinpriza
2026-03-20 04:28:09
(5 months ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-03-20 02:40:00
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:39:54.580834 2026] [security2:error] [pid 2246:tid 2246] [client 83.142.55.89:55849] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cormanleigh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cormanleigh.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abyzeg5btyaUUPRwXZ19TQAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
myagent.site
2026-03-17 17:30:50
(5 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
🇩🇪
kjaerulff
2026-03-11 15:40:11
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
🇺🇸
TPI-Abuse
2026-03-01 07:19:01
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 83.142.55.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 02:18:55.974657 2026] [security2:error] [pid 6413:tid 6413] [client 83.142.55.89:51593] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kunzteam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kunzteam.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaPoX_RBmx2aUeMBNbNzMgAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-08 06:41:30
(6 months ago)
"POST /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack