๐ฌ๐ง
AvonleaConsulting
2026-08-01 22:57:30
(10 hours ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐ฆ๐บ
Anytech
2026-08-01 17:04:51
(16 hours ago)
Blocked by Conn-Monitor
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-08-01 15:06:02
(18 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 08:03:44
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 04:03:29.694660 2026] [security2:error] [pid 1981536:tid 1981536] [client 116.66.189.188:58443] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||semisysteme.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "semisysteme.com"] [uri "/wp-json/wp/v2/users"] [unique_id "am2oUZDHEenZAgmDepi5AQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 14:58:52
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 10:58:35.796377 2026] [security2:error] [pid 3898870:tid 3898870] [client 116.66.189.188:62641] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||constructionloansfunding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "constructionloansfunding.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amy4G4FKOjJ9faHy4ERFxQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-07-31 06:26:50
(2 days ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 17:01:21
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 13:01:07.229125 2026] [security2:error] [pid 802941:tid 802941] [client 116.66.189.188:50313] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||univey.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "univey.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amuDUxlRI_w-uXrIzaWj-wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-07-29 16:20:40
(3 days ago)
[redacted] 116.66.189.188 - - [29/Jul/2026:17:20:30 +0100] "POST /[redacted] HTTP/1.1" 405 6367 0/44 ...
show more
[redacted] 116.66.189.188 - - [29/Jul/2026:17:20:30 +0100] "POST /[redacted] HTTP/1.1" 405 6367 0/44333 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36" [redacted] 116.66.189.188 - - [29/Jul/2026:17:20:38 +0100] "POST /[redacted] HTTP/1.1" 405 6367 0/42547 "-" "Mozilla/5.0 (Windows NT 6.2; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-29 13:48:58
(3 days ago)
Try to access /xmlrpc.php
Web App Attack
Anonymous
2026-07-29 07:00:00
(4 days ago)
Apache probe; attempts=124; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 08:19:26
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:19:11.624875 2026] [security2:error] [pid 4146097:tid 4146097] [client 116.66.189.188:59081] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||activethinkers.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "activethinkers.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amcUf4eiX2YLptbhjdDsCQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 14:50:32
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 116.66.189.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 10:50:16.896194 2026] [security2:error] [pid 7352:tid 7407] [client 116.66.189.188:50530] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||busybeerestaurant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "busybeerestaurant.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amYeqPYJL7JvgrvjilajfgAAAdc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-25 03:43:24
(1 week ago)
[SatJul2505:43:11.6860452026][security2:error][pid2138572:tid2138809][client116.66.189.188:0]ModSecu ...
show more
[SatJul2505:43:11.6860452026][security2:error][pid2138572:tid2138809][client116.66.189.188:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"gipfelbild.com\"][uri\"/xmlrpc.php\"][unique_id\"amQwz9eIjfpPypLOnrbLWQAAAE8\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-24 11:37:31
(1 week ago)
(wordpress) Failed wordpress login from 116.66.189.188 (IN/India/-/-/-/[redacted]): (CF_ENABLE)
Brute-Force
๐ณ๐ฟ
Tripwire
2026-07-24 09:04:15
(1 week ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack