๐บ๐ธ
TPI-Abuse
2026-02-07 08:44:09
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 03:44:03.357132 2026] [security2:error] [pid 25214:tid 25214] [client 98.98.19.200:49184] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||allotrope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "allotrope.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYb7U-bPL23AXjHXc0QKtwAAAB0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 08:06:52
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 03:06:46.085556 2026] [security2:error] [pid 3236844:tid 3236844] [client 98.98.19.200:45164] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cephedanisman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cephedanisman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYbylqls4aVv5a1Jyt6pQAAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 20:46:26
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 15:46:22.627044 2026] [security2:error] [pid 836263:tid 836285] [client 98.98.19.200:37916] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||suncoastequipment.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "suncoastequipment.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYZTHrQqQDe8bpjJaNgClAAAAE4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Shadymint
2026-02-06 20:15:27
(8 months ago)
cms login attempt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 19:23:53
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 14:23:50.321267 2026] [security2:error] [pid 19725:tid 19740] [client 98.98.19.200:57332] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rmgmediagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rmgmediagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYY_xtoeqC_U_ETdrUoXvwAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 18:43:44
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 13:43:40.702736 2026] [security2:error] [pid 15685:tid 15685] [client 98.98.19.200:36576] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||accredo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "accredo.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aYY2XFD7RpqPDUMWLV9ITQAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 18:04:26
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 13:04:22.910020 2026] [security2:error] [pid 13530:tid 13530] [client 98.98.19.200:46266] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marveldirectory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marveldirectory.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYYtJmwYASBhJOBzY658CwAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 17:33:36
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 12:33:29.144885 2026] [security2:error] [pid 32265:tid 32265] [client 98.98.19.200:47922] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honer.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honer.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aYYl6TcnjEnOUwkrXwEEKgAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 17:12:45
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 98.98.19.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 12:12:41.071120 2026] [security2:error] [pid 472644:tid 472644] [client 98.98.19.200:45140] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||markrudin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "markrudin.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYYhCUW4BsKde4u1ZpIwPwAAABo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Sargon Bercot
2024-12-16 16:26:54
(1 year ago)
98.98.19.200 - - [16/Dec/2024:13:26:24 -0300] "GET /wp-admin/ HTTP/1.1" 502 568 "-" "Mozilla/5.0 (Wi ...
show more
98.98.19.200 - - [16/Dec/2024:13:26:24 -0300] "GET /wp-admin/ HTTP/1.1" 502 568 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
98.98.19.200 - - [16/Dec/2024:13:26:25 -0300] "GET /favicon.ico HTTP/1.1" 502 568 "https://sargonbercot.com/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
98.98.19.200 - - [16/Dec/2024:13:26:54 -0300] "GET /wp-admin/ HTTP/1.1" 502 568 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
SSH
๐ง๐ท
Sargon Bercot
2024-12-16 15:48:32
(1 year ago)
98.98.19.200 - - [16/Dec/2024:12:48:31 -0300] "GET / HTTP/1.1" 502 568 "-" "Mozilla/5.0 (Windows NT ...
show more
98.98.19.200 - - [16/Dec/2024:12:48:31 -0300] "GET / HTTP/1.1" 502 568 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
98.98.19.200 - - [16/Dec/2024:12:48:31 -0300] "GET / HTTP/1.1" 502 568 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
98.98.19.200 - - [16/Dec/2024:12:48:31 -0300] "GET /favicon.ico HTTP/1.1" 502 568 "https://auth.sbresults.cloud/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
SSH