πΊπΈ
TPI-Abuse
2026-09-29 09:21:21
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 95.156.136.139 (adsl48mo139.tel.net.ba): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 95.156.136.139 (adsl48mo139.tel.net.ba): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 05:21:16.268415 2026] [security2:error] [pid 31160:tid 31160] [client 95.156.136.139:33892] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||churchbehindthewalls.bridgital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "churchbehindthewalls.bridgital.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aruDDLbodvbVfHWGc20UrwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 07:55:15
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 95.156.136.139 (adsl48mo139.tel.net.ba): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 95.156.136.139 (adsl48mo139.tel.net.ba): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:55:12.449615 2026] [security2:error] [pid 11377:tid 11377] [client 95.156.136.139:55018] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drjasonkolber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drjasonkolber.com"] [uri "/wp-json/wp/v2/users"] [unique_id "artu4C5scvp9hJRKO_6uVgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 03:20:05
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 95.156.136.139 (adsl48mo139.tel.net.ba): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 95.156.136.139 (adsl48mo139.tel.net.ba): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 23:19:59.980403 2026] [security2:error] [pid 28240:tid 28240] [client 95.156.136.139:54336] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tigerpathteam.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tigerpathteam.org"] [uri "/wp-json/wp/v2/users"] [unique_id "arsuXznOIszb2ZE6_r4glQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 16:36:35
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 95.156.136.139 (adsl48mo139.tel.net.ba): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 95.156.136.139 (adsl48mo139.tel.net.ba): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 12:36:30.455221 2026] [security2:error] [pid 15196:tid 15196] [client 95.156.136.139:37970] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newcastle91.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newcastle91.org"] [uri "/wp-json/wp/v2/users"] [unique_id "arqXjil24ayu4BETtE7T9AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-09-28 04:14:52
(3 days ago)
Try to access /xmlrpc.php
Web App Attack
π©πͺ
nyt
2026-09-27 22:13:21
(3 days ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
π²π½
octageeks.com
2026-09-27 04:20:26
(4 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
Anonymous
2026-09-26 23:45:40
(4 days ago)
Web attack blocked by Wordfence on kernoverlegsibbe-ijzeren.nl (3 hits). Reported by CRMON.
Web App Attack
π©πͺ
FeG Deutschland
2026-09-26 23:37:07
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
π©πͺ
LRob
2026-09-26 13:25:51
(4 days ago)
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, ...
show more
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, injected payloads, or the signature of a vulnerability scanner. This is an attack on the sites we host, blocked on sight. Please check the machine behind it for an attack tool or malware. | method: GET | path: /wp-json/wp/v2/users | 2026-09-26 13:25 UTC
show less
Hacking
Web App Attack
πΊπΈ
mnsf
2026-09-26 04:05:15
(5 days ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
Anonymous
2026-09-25 07:39:48
(6 days ago)
WordPress Brute Force
Brute-Force
π²π½
octageeks.com
2026-09-25 04:23:26
(6 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
πΊπΈ
lostswordfish.com
2026-09-24 19:18:03
(6 days ago)
Wordfence waf block on decarcerationnation
Web App Attack