๐บ๐ธ
nationaleventpros.com
2026-06-14 23:58:40
(1 week ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-12 05:40:14
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 01:40:00.803125 2026] [security2:error] [pid 16984:tid 16984] [client 5.183.252.67:49435] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||opere.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "opere.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiubsDyBssal0CCFjLrzzwAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ph
2026-06-11 18:28:25
(1 week ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-05-31 18:19:44
(3 weeks ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-xmlrpc-bf-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 16:27:18
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 12:27:00.678107 2026] [security2:error] [pid 25514:tid 25514] [client 5.183.252.67:31583] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wizind.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wizind.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahm-VB-CWb-3jaOylOM6OwAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-05-26 22:39:07
(4 weeks ago)
[WedMay2700:38:52.6477712026][security2:error][pid2143262:tid2143292][client5.183.252.67:0]ModSecuri ...
show more
[WedMay2700:38:52.6477712026][security2:error][pid2143262:tid2143292][client5.183.252.67:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"morgenstern-swiss.ch\"][uri\"/\"][unique_id\"ahYg_NCRXF13M-nMP2POFgAAABA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 11:16:06
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 07:15:52.281782 2026] [security2:error] [pid 19789:tid 19789] [client 5.183.252.67:54145] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bella-vista.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bella-vista.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahQvaD9ClgZLiJBw_AXV3QAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 13:40:07
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 09:39:49.219691 2026] [security2:error] [pid 9639:tid 9639] [client 5.183.252.67:19469] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||antimu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "antimu.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag8LJY5BjKQ_CW31lrrbpgAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 01:24:38
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 21:24:24.596860 2026] [security2:error] [pid 9376:tid 9376] [client 5.183.252.67:34783] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vendor21.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vendor21.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag5eyFhbu7I1pnn6UJ6bgwAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 21:32:20
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.183.252.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 17:32:02.850125 2026] [security2:error] [pid 8676:tid 8676] [client 5.183.252.67:19567] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||erkan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "erkan.net"] [uri "/wp-json/wp/v2/users"] [unique_id "acBf0rpiX7LYu3Smz0O4IQAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tilellit.pro
2026-03-10 08:11:02
(3 months ago)
Fail2Ban banned 5.183.252.67 for security violations in jail wp-armour. Log: 2026/03/10 08:11:01 [er ...
show more
Fail2Ban banned 5.183.252.67 for security violations in jail wp-armour. Log: 2026/03/10 08:11:01 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 5.183.252.67 | Target: wplogin" , client: 5.183.252.67, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
xmission.com
2026-03-02 14:02:29
(3 months ago)
5.183.252.67 - - [02/Mar/2026:07:02:29 -0700] "POST /wp-login.php HTTP/1.1" 200 2355 "https://dooce. ...
show more
5.183.252.67 - - [02/Mar/2026:07:02:29 -0700] "POST /wp-login.php HTTP/1.1" 200 2355 "https://dooce.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
Anonymous
2025-05-07 06:10:42
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-22 01:01:46
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-19 00:58:03
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH