Anonymous
2026-06-19 14:18:18
(6 days ago)
Attac
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-17 10:45:04
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 06:44:56.967010 2026] [security2:error] [pid 27406:tid 27406] [client 91.198.89.37:39192] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sutherlandyogastudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sutherlandyogastudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajJ6qM5qmZ6NS6vk3LjtwwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 23:56:04
(2 weeks ago)
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0"
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0"
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0"
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0"
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 91.198.89.37 - - [11/Jun/202
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 20:10:21
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:10:17.451446 2026] [security2:error] [pid 30890:tid 30890] [client 91.198.89.37:41780] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soundtrax.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ainEqdVqoqao7Y3oEyhMIQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-06-10 16:20:59
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
πͺπΈ
masterguru
2026-06-10 12:32:42
(2 weeks ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack
π«π·
dynamix
2026-06-09 15:29:14
(2 weeks ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 23:46:06
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 19:46:00.590734 2026] [security2:error] [pid 4557:tid 4557] [client 91.198.89.37:43774] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mccompu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mccompu.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiYCuE6jrubCU4FcfsbfaAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 16:41:02
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 12:40:57.776965 2026] [security2:error] [pid 24315:tid 24315] [client 91.198.89.37:46856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiWfGSMQqAR_fim2YUgutgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 03:12:31
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 23:12:26.611845 2026] [security2:error] [pid 27701:tid 27701] [client 91.198.89.37:39268] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lahamradio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiThmkU_36oRz7I2_CjJiwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 19:18:58
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 15:18:53.166936 2026] [security2:error] [pid 17831:tid 17831] [client 91.198.89.37:52250] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stellabluesales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stellabluesales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiRyneopQe78EMEIC0UXGAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 06:43:53
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 02:43:46.621137 2026] [security2:error] [pid 3291:tid 3291] [client 91.198.89.37:40612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.randymcelroy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.randymcelroy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiPBollUNV3_xNCuJj8AiAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Mangelot Hosting
2026-06-05 23:55:55
(2 weeks ago)
(wp_login_try) srv104 WP Login Attempt 91.198.89.37 (PL/Poland/www.manierait.pl): 10 in the last 360 ...
show more
(wp_login_try) srv104 WP Login Attempt 91.198.89.37 (PL/Poland/www.manierait.pl): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-05 22:09:26
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 18:09:18.392920 2026] [security2:error] [pid 28796:tid 28796] [client 91.198.89.37:40958] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.wild-goose.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.wild-goose.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aiNJDuTtInzSNF715tqupwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-05 20:42:13
(2 weeks ago)
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:43.0) Gecko/20100101 Firefox/43.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0"
[redacted] 91.198.89.37 - - [05/Jun/202
...
show less
Hacking
Web App Attack