πΊπΈ
TPI-Abuse
2026-06-23 10:37:44
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 06:37:38.333731 2026] [security2:error] [pid 19248:tid 19248] [client 187.77.50.147:59130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||makaihe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "makaihe.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajph8sO9T3Q2blyEE9x0TwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
4server
2026-06-23 06:15:09
(1 day ago)
[TueJun2308:15:05.1555412026][security2:error][pid965390:tid965651][client187.77.50.147:0]ModSecurit ...
show more
[TueJun2308:15:05.1555412026][security2:error][pid965390:tid965651][client187.77.50.147:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"mondo-it.ch\"][uri\"/xmlrpc.php\"][unique_id\"ajokaT3_TOLAy8Bp4thqEQAAAQQ\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-23 04:41:19
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 00:41:11.673976 2026] [security2:error] [pid 31721:tid 31721] [client 187.77.50.147:51986] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coyotebytes.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coyotebytes.net"] [uri "/wp-json/wp/v2/users/8"] [unique_id "ajoOZz8Re9ByFsQXJaancwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-06-23 04:15:25
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
pltcldvlpr
2026-06-22 20:44:40
(1 day ago)
CMS/framework probe: 187.77.50.147 - - [22/Jun/2026:22:44:39 +0200] "GET /xmlrpc.php HTTP/2.0" 404 5 ...
show more
CMS/framework probe: 187.77.50.147 - - [22/Jun/2026:22:44:39 +0200] "GET /xmlrpc.php HTTP/2.0" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" asn=47583 org="Hostinger International Limited" country=BR
...
show less
Web App Attack
π¨π¦
zXero
2026-06-22 14:08:47
(1 day ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
π©πͺ
Holger
2026-06-22 05:09:39
(2 days ago)
WordPress WebAttack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 12:55:19
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 08:55:16.567595 2026] [security2:error] [pid 12951:tid 12951] [client 187.77.50.147:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||duct.cloudex.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "duct.cloudex.click"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajaNtFQ0ay_HUOWx4SlMMgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-06-20 04:07:26
(4 days ago)
Wordpress malicious attack:[octawp]
Web App Attack
π©πͺ
FeG Deutschland
2026-06-20 01:36:43
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 00:46:46
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:46:42.180781 2026] [security2:error] [pid 22687:tid 22687] [client 187.77.50.147:50960] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bbproductionsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bbproductionsonline.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "ajXi8pj9KwkYd0rYXjxDNwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-19 14:21:14
(4 days ago)
187.77.50.147 - - [19/Jun/2026:16:21:08 +0200] "GET /wp-login.php HTTP/2.0" 200 4003 "-" "Mozilla/5. ...
show more
187.77.50.147 - - [19/Jun/2026:16:21:08 +0200] "GET /wp-login.php HTTP/2.0" 200 4003 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-19 02:42:37
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 22:42:30.492667 2026] [security2:error] [pid 27660:tid 27660] [client 187.77.50.147:57858] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||guldunyayayinlari.handankoc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "guldunyayayinlari.handankoc.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajSslvweSYgAvWpmoEbfTwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-19 02:21:25
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 187.77.50.147 (srv1406816.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 22:21:19.758679 2026] [security2:error] [pid 17163:tid 17175] [client 187.77.50.147:59850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tkfay.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajSnn0Eri8vn299dKSl2fgAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-06-19 01:45:40
(5 days ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 187.77.50.147 (BR/Brazil/srv1406816.hstgr.clo ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 187.77.50.147 (BR/Brazil/srv1406816.hstgr.cloud): 1 in the last 3600 secs (0-195)
show less
Hacking