๐บ๐ธ
TPI-Abuse
2026-06-15 01:18:23
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 112.208.66.228 (112.208.66.228.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 112.208.66.228 (112.208.66.228.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:18:20.237921 2026] [security2:error] [pid 11692:tid 11694] [client 112.208.66.228:50987] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ethicmark.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ethicmark.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai9S3BnntfI0eOF6-sS8lAAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:51:38
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 112.208.66.228 (112.208.66.228.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 112.208.66.228 (112.208.66.228.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:51:32.551981 2026] [security2:error] [pid 18164:tid 18164] [client 112.208.66.228:52264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||elgatocapa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "elgatocapa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai9MlDCicsf5Ic6pMRc7ZQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 00:08:40
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
4server
2026-06-14 23:13:21
(4 hours ago)
[MonJun1501:13:17.6239042026][security2:error][pid2397636:tid2397670][client112.208.66.228:0]ModSecu ...
show more
[MonJun1501:13:17.6239042026][security2:error][pid2397636:tid2397670][client112.208.66.228:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"dellafoglia.ch\"][uri\"/xmlrpc.php\"][unique_id\"ai81jVJCBUvnhLQgbZXbNAAAABc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:21:28
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 112.208.66.228 (112.208.66.228.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 112.208.66.228 (112.208.66.228.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:21:23.754223 2026] [security2:error] [pid 18638:tid 18638] [client 112.208.66.228:51261] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coolerboxes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coolerboxes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai8pY3hmvXkaI5jViUzYtQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-14 04:20:16
(23 hours ago)
Try to access /xmlrpc.php
Web App Attack
Anonymous
2026-06-14 04:20:09
(23 hours ago)
(wordpress) Failed wordpress login from 112.208.66.228 (PH/Philippines/112.208.66.228.pldt.net)
Brute-Force
๐ณ๐ฟ
Tripwire
2026-06-13 23:17:31
(1 day ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-13 22:25:44
(1 day ago)
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-06-13 13:02:16
(1 day ago)
[SatJun1315:02:10.3292462026][security2:error][pid1155204:tid1155294][client112.208.66.228:0]ModSecu ...
show more
[SatJun1315:02:10.3292462026][security2:error][pid1155204:tid1155294][client112.208.66.228:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"simireinigung.ch\"][uri\"/xmlrpc.php\"][unique_id\"ai1U0tQR_2L686OuBKXY2gAAAMA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-12 23:41:31
(2 days ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 20:44:42
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 112.208.66.228 (112.208.66.228.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 112.208.66.228 (112.208.66.228.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 16:44:38.848794 2026] [security2:error] [pid 6528:tid 6528] [client 112.208.66.228:53591] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||campnecon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "campnecon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aixvtlk0gVLOSjOAL7SEUQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-12 00:12:17
(3 days ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-06-11 21:14:19
(3 days ago)
-:443 112.208.66.228 - - [11/Jun/2026:23:14:18 +0200] - "POST /xmlrpc.php HTTP/1.1" 403 6401 "-" "Mo ...
show more
-:443 112.208.66.228 - - [11/Jun/2026:23:14:18 +0200] - "POST /xmlrpc.php HTTP/1.1" 403 6401 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐บ๐ธ
TheMadBeaker
2025-07-03 00:48:34
(11 months ago)
Fail2Ban Ban Triggered
HTTP Exploit Attempt
Brute-Force
Web App Attack