๐บ๐ธ
TPI-Abuse
2026-09-01 02:38:00
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:37:52.502615 2026] [security2:error] [pid 21907:tid 21930] [client 91.245.236.168:40909] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woofnrose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woofnrose.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apY6gG5-TbcRZiBD8lwbbgAAAJU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 10:55:07
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 06:55:03.595161 2026] [security2:error] [pid 25436:tid 25436] [client 91.245.236.168:47277] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||truecontrarian.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "truecontrarian.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoWLh3dkfMharFvCut75QAAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 10:29:21
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 06:29:16.413952 2026] [security2:error] [pid 10129:tid 10129] [client 91.245.236.168:50061] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grayowl.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grayowl.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoWFfFRa3ets7CQF1mp_8AAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 15:34:38
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 11:34:33.584692 2026] [security2:error] [pid 17755:tid 17755] [client 91.245.236.168:57247] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonefrog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonefrog.com"] [uri "/wp-json/wp/v2/users"] [unique_id "an81iSVUR1crRhKuI323SgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-14 12:57:21
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
MM-bot
2026-07-31 22:28:36
(1 month ago)
URL-probe: HTTP/1.1 POST request on /xmlrpc.php (2026-08-01 00:28:36 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 04:01:14
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:01:08.479504 2026] [security2:error] [pid 400068:tid 400068] [client 91.245.236.168:35813] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||madronabluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "madronabluff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amQ1BHPGt8Fx634moEa9SAAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-07-19 13:32:24
(1 month ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-02 05:21:31
(2 months ago)
tilellit/wp-armour-ban
Hacking
๐ซ๐ท
Tilellit.PRO
2026-06-29 08:27:11
(2 months ago)
Fail2Ban banned 91.245.236.168 for security violations in jail wp-armour. Log: 2026/06/29 08:27:10 [ ...
show more
Fail2Ban banned 91.245.236.168 for security violations in jail wp-armour. Log: 2026/06/29 08:27:10 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 91.245.236.168 | Target: wplogin" , client: 91.245.236.168, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-27 11:48:40
(2 months ago)
Fail2Ban banned 91.245.236.168 for security violations in jail wp-armour. Log: 2026/06/27 11:48:39 [ ...
show more
Fail2Ban banned 91.245.236.168 for security violations in jail wp-armour. Log: 2026/06/27 11:48:39 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 91.245.236.168 | Target: wplogin" , client: 91.245.236.168, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-05-21 20:16:25
(3 months ago)
Fail2Ban banned 91.245.236.168 for security violations in jail wp-armour. Log: 2026/05/21 20:16:25 [ ...
show more
Fail2Ban banned 91.245.236.168 for security violations in jail wp-armour. Log: 2026/05/21 20:16:25 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 91.245.236.168 | Target: wplogin" , client: 91.245.236.168, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-05-07 19:26:07
(3 months ago)
Fail2Ban banned 91.245.236.168 for security violations in jail wp-armour. Log: 2026/05/07 19:26:06 [ ...
show more
Fail2Ban banned 91.245.236.168 for security violations in jail wp-armour. Log: 2026/05/07 19:26:06 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 91.245.236.168 | Target: wplogin" , client: 91.245.236.168, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐จ๐ญ
backslash
2026-05-06 12:42:00
(3 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-03 14:28:58
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 10:28:51.419530 2026] [security2:error] [pid 3943:tid 3955] [client 91.245.236.168:56611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barnetts.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barnetts.us"] [uri "/wp-json/wp/v2/users"] [unique_id "afdbo3k_DghlLjkOBuduMwAAAEY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack