๐บ๐ธ
TPI-Abuse
2026-06-19 19:52:30
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 129.210.115.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.210.115.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 15:52:26.839549 2026] [security2:error] [pid 16350:tid 16350] [client 129.210.115.104:27458] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jonasrimkunas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jonasrimkunas.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWd-viJIC--b23PZQ3N_wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 16:28:21
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 129.210.115.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.210.115.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 12:28:15.238164 2026] [security2:error] [pid 26801:tid 26801] [client 129.210.115.104:8780] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drjasonkolber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drjasonkolber.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajVuHzuGMztu0yb9S8OqfQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 15:51:58
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 129.210.115.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.210.115.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 11:51:50.197990 2026] [security2:error] [pid 18255:tid 18255] [client 129.210.115.104:46600] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||davesievers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "davesievers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajVllmanJ0kGCijeWRYMYQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-06-19 13:48:04
(8 hours ago)
Repeated request on blocked xmlrpc.php.
129.210.115.104 - - [19/Jun/2026:15:48:01 +0200] "POST /xmlr ...
show more
Repeated request on blocked xmlrpc.php.
129.210.115.104 - - [19/Jun/2026:15:48:01 +0200] "POST /xmlrpc.php HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
show less
Web App Attack
Anonymous
2026-06-19 13:00:10
(9 hours ago)
[redacted] 129.210.115.104 - - [19/Jun/2026:14:58:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" ...
show more
[redacted] 129.210.115.104 - - [19/Jun/2026:14:58:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (Windows NT 6.2; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/15.0.0.0 Safari/537.36"
[redacted] 129.210.115.104 - - [19/Jun/2026:14:59:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/79.0.0.0 Safari/537.36"
[redacted] 129.210.115.104 - - [19/Jun/2026:14:59:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/60.0.0.0 Safari/537.36"
[redacted] 129.210.115.104 - - [19/Jun/2026:14:59:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.0.0 Safari/537.36"
[redacted] 129.210.115.104 - - [19/Jun/2026:14:59:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (X11;
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 08:49:38
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 129.210.115.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.210.115.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 04:49:30.431911 2026] [security2:error] [pid 24257:tid 24257] [client 129.210.115.104:20190] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||richmondrents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "richmondrents.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajUCmkaJmdyXceNf2xhYdgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-19 06:24:07
(16 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack
Anonymous
2023-09-17 14:58:26
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack