๐บ๐ธ
TPI-Abuse
2026-06-23 15:51:20
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 11:51:13.551275 2026] [security2:error] [pid 32232:tid 32232] [client 85.118.245.29:33592] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.texascottagebakers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.texascottagebakers.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajqrcW7GMUBkkjMsu3kWIQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-22 22:41:15
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-22 22:34:32
(3 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 11:31:03
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 07:30:55.655702 2026] [security2:error] [pid 2041:tid 2041] [client 85.118.245.29:35224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.arthuryeung.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.arthuryeung.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkc7-_SGZlV6LOz9zVPHQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 03:18:13
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 23:18:08.263803 2026] [security2:error] [pid 13479:tid 13479] [client 85.118.245.29:40806] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wwfstudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wwfstudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajipcJ8Kuub5Fqh2jJsjggAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 00:17:57
(4 days ago)
[server.tmg.gr] httpd-suspicious-path: sites=aidshep2017.gr; logs=/var/log/httpd/domains/aidshep2017 ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=aidshep2017.gr; logs=/var/log/httpd/domains/aidshep2017.gr.log; samples=/wp-json/wp/v2/users | /?author=1 | /?author=2
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-06-18 14:47:50
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 09:03:48
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 05:03:43.345980 2026] [security2:error] [pid 13330:tid 13350] [client 85.118.245.29:40160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leadingedgesupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leadingedgesupply.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajO0b2DytWbfRLKxnSyQygAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:41:07
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:40:58.412885 2026] [security2:error] [pid 4389:tid 4389] [client 85.118.245.29:45618] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doctorbalog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doctorbalog.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-QanjworIs0P6Ea-hU8AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:38:39
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:38:35.419231 2026] [security2:error] [pid 28831:tid 28831] [client 85.118.245.29:40014] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bosdkbook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bosdkbook.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai9XmxFd0QP_zYhY2dBFgwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-14 22:32:09
(1 week ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-13 22:30:42
(1 week ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 17:57:05
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 13:57:00.560800 2026] [security2:error] [pid 12738:tid 12738] [client 85.118.245.29:58808] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bikinitweets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bikinitweets.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai2Z7Dtg_H9HrbI6MACBLQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 13:39:03
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 85.118.245.29 (bisbaturgell.planalfa.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 09:38:57.256336 2026] [security2:error] [pid 17491:tid 17491] [client 85.118.245.29:39626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ixd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ixd.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ai1dcdNutcepF04P0ko6xgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 09:44:40
(1 week ago)
[redacted] 85.118.245.29 - - [13/Jun/2026:11:44:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 85.118.245.29 - - [13/Jun/2026:11:44:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:42.0) Gecko/20100101 Firefox/42.0"
[redacted] 85.118.245.29 - - [13/Jun/2026:11:44:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0"
[redacted] 85.118.245.29 - - [13/Jun/2026:11:44:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0"
[redacted] 85.118.245.29 - - [13/Jun/2026:11:44:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0"
[redacted] 85.118.245.29 - - [13/Jun/2026:11:44:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
[redacted] 85.118.245.29 - - [13/J
...
show less
Hacking
Web App Attack