๐ณ๐ฑ
wlt-blocker
2026-06-12 04:58:17
(3 hours ago)
Unauthorized access to webpage admin
Web App Attack
๐ซ๐ฎ
stinpriza
2026-06-12 03:05:47
(5 hours ago)
Web App Attack
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-11 19:00:11
(13 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-06-11 10:46:20
(21 hours ago)
2026-06-11 @ 12:46:20 (CET) ~ Blocked for trying to access: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 09:14:29
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 115.247.87.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 115.247.87.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 05:14:24.391105 2026] [security2:error] [pid 20541:tid 20670] [client 115.247.87.98:36632] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||giere.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "giere.us"] [uri "/wp-json/wp/v2/users"] [unique_id "aip8cOeo8of_6A-OdhsgJAAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
ip4.tw
2026-06-10 13:12:01
(1 day ago)
Malicious web scan
Hacking
Web App Attack
๐ซ๐ท
/dev/null
2026-06-10 13:11:01
(1 day ago)
Known malicious PHP file or CMS probe
Brute-Force
๐ฉ๐ช
strxmpp
2026-06-10 11:59:03
(1 day ago)
115.247.87.98 - - [10/Jun/2026:13:59:02 +0200] "POST /xmlrpc.php HTTP/1.1" 404 4246 "-" "Mozilla/5.0 ...
show more
115.247.87.98 - - [10/Jun/2026:13:59:02 +0200] "POST /xmlrpc.php HTTP/1.1" 404 4246 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/14.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
๐บ๐ธ
jcbriar
2026-06-10 09:28:14
(1 day ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 06:26:42
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 115.247.87.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 115.247.87.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 02:26:34.766283 2026] [security2:error] [pid 10372:tid 10372] [client 115.247.87.98:63374] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ardeeapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ardeeapps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aikDmuss_2JpPVLL7Y0IdQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-09 17:26:33
(2 days ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:53:09
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 115.247.87.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 115.247.87.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:53:04.340387 2026] [security2:error] [pid 15079:tid 15079] [client 115.247.87.98:61840] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||citizensforsanity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "citizensforsanity.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aifigGVfXMcCowl4DabYogAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 07:46:04
(3 days ago)
Bot / scanning and/or hacking attempts: GET /xmlrpc.php HTTP/1.1, POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 00:10:56
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 115.247.87.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 115.247.87.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:10:50.878664 2026] [security2:error] [pid 2807:tid 2807] [client 115.247.87.98:56021] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||somehand.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "somehand.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aidaCgte4-a7aGBMJ4-DwQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 19:05:02
(3 days ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (14/60 min)'; Requests=14
Port Scan