🇺🇸
TPI-Abuse
2026-09-09 06:35:42
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonlin ...
show more
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonline.telia.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:35:34.777355 2026] [security2:error] [pid 778130:tid 778145] [client 95.199.140.144:33738] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||plumeraproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "plumeraproductions.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqD-NgNjybtgHJUbi9nWwQAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-09-09 06:04:03
(19 hours ago)
Wordfence waf block on robdarnell
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-09 05:59:41
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-09 05:58:25
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:43:05
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonlin ...
show more
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonline.telia.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:42:59.102896 2026] [security2:error] [pid 11785:tid 11785] [client 95.199.140.144:35276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tomartsmedia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tomartsmedia.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDx45qTaWPsHGj647pGGgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:43:13
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonlin ...
show more
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonline.telia.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:43:09.497855 2026] [security2:error] [pid 3864:tid 3864] [client 95.199.140.144:43400] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||meganmurph.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "meganmurph.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDVzfONm0Yenqurw0h0PwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gigatech
2026-09-09 02:35:04
(23 hours ago)
Webserver Probing
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:11:14
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonlin ...
show more
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonline.telia.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:11:08.916621 2026] [security2:error] [pid 8653:tid 8653] [client 95.199.140.144:38870] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sfgardening.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sfgardening.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDAPJSrb_vq0hq9bEi7dAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 02:00:03
(23 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026- ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026-09-09 02:00 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:43:20
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonlin ...
show more
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonline.telia.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:43:15.839641 2026] [security2:error] [pid 5044:tid 5044] [client 95.199.140.144:54674] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lysedzija.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC5s4EreszscvVtnqY1vQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 01:15:43
(1 day ago)
Web attack blocked by Wordfence on 1valkenburg.nl (1 hit). Reported by CRMON.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:12:34
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonlin ...
show more
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonline.telia.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:12:30.403817 2026] [security2:error] [pid 2299:tid 2299] [client 95.199.140.144:35406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mundanestudies.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mundanestudies.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCkbljItxGOTPkoI0pQPwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 21:58:28
(1 day ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /wp-json/wp/v2/users/me | 2026-09-08 21:58 UTC
show less
Bad Web Bot
🇩🇪
FeG Deutschland
2026-09-08 21:18:47
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:34:49
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonlin ...
show more
(mod_security) mod_security (id:225170) triggered by 95.199.140.144 (host-95-199-140-144.mobileonline.telia.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:34:42.005245 2026] [security2:error] [pid 1065:tid 1138] [client 95.199.140.144:52922] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dontbeajerklikeyourwork.com.teritemme.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dontbeajerklikeyourwork.com.teritemme.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBxYjIf5E13drevx2g1VAAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack