๐ฉ๐ช
thesimonmanuel
2026-10-07 15:54:05
(1 day ago)
165.22.50.112 - - [07/Oct/2026:21:24:04 +0530] "GET /readme.html HTTP/2.0" 200 3030 "-" "Mozilla/5.0 ...
show more
165.22.50.112 - - [07/Oct/2026:21:24:04 +0530] "GET /readme.html HTTP/2.0" 200 3030 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 15:43:29
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:43:21.760656 2026] [security2:error] [pid 32376:tid 32376] [client 165.22.50.112:41600] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rambleandprose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rambleandprose.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asZomdBsb2kNj1bnXV1Y-QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 13:45:11
(1 day ago)
2026-10-07T13:45:10.495557+00:00 instance-20260804-1025 wordpress(jumarpab.co)[454876]: Blocked user ...
show more
2026-10-07T13:45:10.495557+00:00 instance-20260804-1025 wordpress(jumarpab.co)[454876]: Blocked user enumeration attempt from 165.22.50.112
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 13:31:24
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:31:16.535537 2026] [security2:error] [pid 5749:tid 5749] [client 165.22.50.112:42724] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||letmespeakpodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "letmespeakpodcast.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asZJpE79ZQJrn1NdsFvqxwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:59:39
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:59:32.838004 2026] [security2:error] [pid 651:tid 651] [client 165.22.50.112:60660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clayrivers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clayrivers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asZCNMJWhBV9y1AMmkdxrgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 11:28:50
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:28:44.206824 2026] [security2:error] [pid 29478:tid 29478] [client 165.22.50.112:48216] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||washcountyfair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "washcountyfair.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asYs7O1UutfrFI6sctq2EAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 10:28:57
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:28:53.393954 2026] [security2:error] [pid 1233:tid 1233] [client 165.22.50.112:36754] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||esysapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "esysapps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asYe5X4HOg0xqArKsYlzagAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-07 09:03:52
(1 day ago)
2.260 requests from abuseipdb.com blacklisted IP (1yr10mos3w)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 08:13:52
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:13:45.380269 2026] [security2:error] [pid 7380:tid 7380] [client 165.22.50.112:58510] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adlc18.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adlc18.org"] [uri "/wp-json/wp/v2/users"] [unique_id "asX_OZA8X0dtFSx5JX85JAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 07:10:56
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 03:10:53.249872 2026] [security2:error] [pid 21116:tid 21116] [client 165.22.50.112:53278] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cathybermanmft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cathybermanmft.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asXwffbaCjNvN38kqgT8TAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2026-10-07 06:29:48
(1 day ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2026-10-07 05:41:30
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:41:24.490996 2026] [security2:error] [pid 27611:tid 27643] [client 165.22.50.112:57412] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||culturallyyours.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "culturallyyours.org"] [uri "/wp-json/wp/v2/users"] [unique_id "asXbhIxvnpRNN0i11dG9gQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-10-07 03:58:38
(1 day ago)
Honeypot triggered: /wp-json/wp/v2/users on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; ...
show more
Honeypot triggered: /wp-json/wp/v2/users on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36. Method: GET
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:38:44
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.22.50.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:38:40.134000 2026] [security2:error] [pid 2681:tid 2681] [client 165.22.50.112:42836] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||automatebi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "automatebi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asWGgN9H-yGqIT4XBl80VgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Security_Whaller
2026-10-06 21:43:24
(2 days ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack