๐บ๐ธ
TPI-Abuse
2026-09-20 11:44:24
(51 minutes ago)
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:44:17.113829 2026] [security2:error] [pid 31290:tid 31290] [client 84.200.41.7:55976] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cubbylure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cubbylure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq_HEW-2XxgPROsiVIYqVgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 07:04:54
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 03:04:51.251695 2026] [security2:error] [pid 16895:tid 16895] [client 84.200.41.7:52946] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.blaslandsporthorses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.blaslandsporthorses.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq-Fk1OjcigIhFsNgeLkfwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 06:49:37
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 02:49:30.748564 2026] [security2:error] [pid 24489:tid 24489] [client 84.200.41.7:43880] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mindroothealth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mindroothealth.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq-B-hPkuGPdR2vvYcZjsQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-20 06:33:56
(6 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 84.200.41.7 (DE/Germany/web05.genx-host.de): 1 ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 84.200.41.7 (DE/Germany/web05.genx-host.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 84.200.41.7 - - [20/Sep/2026:08:33:52 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12119 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" host=johnfante.info
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 23:54:57
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 19:54:51.559339 2026] [security2:error] [pid 25143:tid 25247] [client 84.200.41.7:35232] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.darrylrichards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.darrylrichards.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8gy5L2bky97GjjIHaYogAAAg0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 22:07:15
(14 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 19:33:31
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:33:26.339834 2026] [security2:error] [pid 9380:tid 9380] [client 84.200.41.7:43998] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greatchristianadventure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greatchristianadventure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7jhi67pBL0BsYWYKFMWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-09-19 18:30:16
(18 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 16:41:27
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 12:41:22.306189 2026] [security2:error] [pid 27521:tid 27521] [client 84.200.41.7:47794] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||scrunchiebuttbikini.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "scrunchiebuttbikini.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq67MqmdyFqoxMGzm2E8nAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-19 15:30:23
(21 hours ago)
84.200.41.7 - - [19/Sep/2026:15:29:24 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Wi ...
show more
84.200.41.7 - - [19/Sep/2026:15:29:24 +0000] "GET /?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0" "-" edge="84.200.41.7"
84.200.41.7 - - [19/Sep/2026:15:29:25 +0000] "GET /?author=3 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" edge="84.200.41.7"
84.200.41.7 - - [19/Sep/2026:15:29:28 +0000] "GET /?author=4 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0" "-" edge="84.200.41.7"
84.200.41.7 - - [19/Sep/2026:15:29:30 +0000] "GET /?author=5 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" edge="84.200.41.7"
84.200.41.7 - - [19/Sep/2026:15:29:31 +0000] "GET /?author=6 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0" "-" edge="84.200.41.7"
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 13:54:47
(22 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 11:40:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 84.200.41.7 (web05.genx-host.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:40:47.473609 2026] [security2:error] [pid 7570:tid 7570] [client 84.200.41.7:43626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hawaiivacations.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hawaiivacations.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq50v1fR7XQVWjvgrf-OpgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 11:36:18
(1 day ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐ฉ๐ช
LRob
2026-09-19 10:14:31
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-19 10:14 UTC
show less
Hacking
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-01 04:14:04
(2 weeks ago)
Wordpress malicious attack:[octawp]
Web App Attack