🇺🇸
TPI-Abuse
2026-09-05 05:21:17
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 01:21:09.058265 2026] [security2:error] [pid 32161:tid 32161] [client 91.245.236.213:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||antitribu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "antitribu.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apumxYHzEedXxDbCfiVtCQAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:10:16
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:10:10.993272 2026] [security2:error] [pid 24625:tid 24625] [client 91.245.236.213:29979] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pc-rack.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pc-rack.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apslovN2WgWbaTE2q1ntlwAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-17 16:25:04
(3 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-08-11 14:25:03
(4 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇺🇸
kosada.com
2026-08-07 10:12:07
(1 month ago)
Web vulnerability probing: /wp-json/wp/v2/users
Web App Attack
🇵🇱
strefapi_com
2026-08-05 19:55:43
(1 month ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇩🇪
Tha_14
2026-08-02 06:44:11
(1 month ago)
Attempt to log in with non-existing username: info
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-31 14:59:51
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 10:59:44.261815 2026] [security2:error] [pid 614447:tid 614447] [client 91.245.236.213:52253] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||onyxcc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "onyxcc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amy4YJNyw_cIVz7Dhej8kgAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
DRI
2026-07-29 01:24:25
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
🇩🇪
FeG Deutschland
2026-07-26 18:49:58
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-07-25 05:57:22
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 01:57:15.513724 2026] [security2:error] [pid 21704:tid 21704] [client 91.245.236.213:27207] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||szeliga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "szeliga.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amRQO54yf_Jx649FY30R9QAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 04:02:49
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:02:45.571753 2026] [security2:error] [pid 1731715:tid 1731715] [client 91.245.236.213:28045] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mycherishedteddies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mycherishedteddies.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amGSZSJNPleiSwcTHHOvPgAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-17 04:26:28
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 00:26:22.828908 2026] [security2:error] [pid 17390:tid 17390] [client 91.245.236.213:32865] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jmgrigg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jmgrigg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "almu7sfHZVj9pespSMW4sQAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-07-12 02:06:01
(1 month ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇩🇪
FeG Deutschland
2026-07-10 21:49:46
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack