🇺🇸
TPI-Abuse
2026-09-09 04:21:34
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:21:26.824476 2026] [security2:error] [pid 8422:tid 8422] [client 91.150.203.20:63634] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgegourmet.visionremota.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgegourmet.visionremota.info"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDexmPlABCsPOo9llj0dwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
ELYAZ
2026-09-09 02:55:26
(1 day ago)
(wordpress) Failed wordpress login from 91.150.203.20 (PL/Poland/91-150-203-20.dynamic.play.pl): (C ...
show more
(wordpress) Failed wordpress login from 91.150.203.20 (PL/Poland/91-150-203-20.dynamic.play.pl): (CF_ENABLE)
show less
Brute-Force
🇫🇷
masterguru
2026-09-09 01:59:27
(1 day ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 91.150.203.20 (PL/Poland/91-150-203-20.dynami ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 91.150.203.20 (PL/Poland/91-150-203-20.dynamic.play.pl): 1 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-09 01:02:46
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:02:38.632129 2026] [security2:error] [pid 19290:tid 19290] [client 91.150.203.20:63740] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yuichiro.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yuichiro.us"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCwLpR6t1OkI79SK23tCAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:16:29
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:16:21.592999 2026] [security2:error] [pid 3913:tid 3913] [client 91.150.203.20:61617] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lambert-heating-and-air.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqClVR1hytIsKNsKCy2QpwAAAHQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:42:59
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:42:54.174443 2026] [security2:error] [pid 21757:tid 21757] [client 91.150.203.20:63754] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grouchytrump.com.gregquinn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grouchytrump.com.gregquinn.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCdfiZOzTRuEnkxACHe2QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 17:51:43
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:11:31
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): ...
show more
(mod_security) mod_security (id:225170) triggered by 91.150.203.20 (91-150-203-20.dynamic.play.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:11:25.167749 2026] [security2:error] [pid 9444:tid 9444] [client 91.150.203.20:61628] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oakglenhouse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oakglenhouse.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBBvSYpJ5vtnbcoSBupqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack