๐บ๐ธ
AutoAddOnStore
2026-04-07 17:53:00
(5 months ago)
attempted to exploit server files
Spoofing
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
4server
2026-04-07 08:50:15
(5 months ago)
[TueApr0710:50:10.4796832026][security2:error][pid903974:tid904068][client103.165.69.39:0]ModSecurit ...
show more
[TueApr0710:50:10.4796832026][security2:error][pid903974:tid904068][client103.165.69.39:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"112\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"bestrestmaterassi.ch\"][uri\"/xmlrpc.php\"][unique_id\"adTFQqy7wFi2aLD5HTIeQQAAAQA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-06 14:50:08
(5 months ago)
Unauthorized access to webpage admin
Web App Attack
๐ณ๐ฟ
Tripwire
2026-04-06 02:31:12
(5 months ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-04-05 18:11:39
(5 months ago)
(wordpress) Failed wordpress login from 103.165.69.39 (IN/India/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-05 12:11:35
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 103.165.69.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 103.165.69.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 08:11:31.504028 2026] [security2:error] [pid 15560:tid 15560] [client 103.165.69.39:54807] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abeltours.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abeltours.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adJRc-Rb7OOhNggQR7hhOwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-04-04 22:26:03
(5 months ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-04 18:17:21
(5 months ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 11:37:19
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 103.165.69.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 103.165.69.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 07:37:13.861882 2026] [security2:error] [pid 26703:tid 26703] [client 103.165.69.39:59350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||36sovereignchambers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "36sovereignchambers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adD36SQMx3ReyRZJ5zQaSwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 09:22:55
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 103.165.69.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 103.165.69.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 05:22:51.294458 2026] [security2:error] [pid 7022:tid 7022] [client 103.165.69.39:65343] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||casaluzislamujeres.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "casaluzislamujeres.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adDYa_qS-VNppY50aTy6tgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-04-04 07:02:55
(5 months ago)
2026-04-04T08:02:54.299334+01:00 ipoac.nl wordpress(-)-: XML-RPC authentication failure for-from 103 ...
show more
2026-04-04T08:02:54.299334+01:00 ipoac.nl wordpress(-)-: XML-RPC authentication failure for-from 103.165.69.39
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 09:55:00
(7 months ago)
(mod_security) mod_security (id:211030) triggered by 103.165.69.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211030) triggered by 103.165.69.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 04:54:55.710308 2026] [security2:error] [pid 14035:tid 14035] [client 103.165.69.39:42762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at ARGS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "17"] [id "211030"] [rev "3"] [msg "COMODO WAF: LDAP Injection Attack||verenacastle.com|F|2"] [data "Matched Data: ('~'||( found within ARGS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "verenacastle.com"] [uri "/g12contact.php"] [unique_id "aZbd77-Vc9MIRigJtNdzVgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-24 05:50:25
(9 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH