๐ฉ๐ช
LRob.fr
2025-08-07 10:45:23
(10 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-04 03:27:41
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 03 23:27:33.495006 2025] [security2:error] [pid 1152:tid 1152] [client 129.226.145.114:64140] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kbalan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kbalan.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJAopT3ZlSkA-jA6j--cHQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-04 02:23:12
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 03 22:23:07.025933 2025] [security2:error] [pid 2401:tid 2401] [client 129.226.145.114:65089] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.schlegelcreative.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJAZiynVTnwfbaP35aKi5QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2025-08-03 22:59:25
(10 months ago)
Web App Attack
Web App Attack
Anonymous
2025-08-03 05:43:31
(10 months ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-31 04:07:34
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 31 00:07:26.914821 2025] [security2:error] [pid 30547:tid 30547] [client 129.226.145.114:62305] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cayman-islands-real-estate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cayman-islands-real-estate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIrr_iahrZIU42jLTiDwYQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-30 21:19:27
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 30 17:19:19.851879 2025] [security2:error] [pid 3168:tid 3249] [client 129.226.145.114:55941] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arizonasolutionsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arizonasolutionsgroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIqMV56rRBhOXRA5ngy3HAAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-30 19:46:12
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 129.226.145.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 30 15:46:04.866146 2025] [security2:error] [pid 29185:tid 29185] [client 129.226.145.114:62714] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.havenlaneministries.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.havenlaneministries.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIp2fFOKctQNviNCQdr6PwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-25 20:30:10
(10 months ago)
Failed Wordpress Logins
Web App Attack
๐ฉ๐ช
F242
2025-07-18 03:06:45
(11 months ago)
Wordpress soft lock
Web App Attack
๐ฎ๐น
mgarofano80
2025-07-18 01:50:47
(11 months ago)
Brute-Force
Web App Attack
๐จ๐ฟ
ddw
2025-07-18 01:03:50
(11 months ago)
WordPress XMLRPC.PHP Access Attempt.
Hacking
Web App Attack
Anonymous
2025-07-17 18:13:18
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
neckaralb-admin.de
2025-07-17 15:59:19
(11 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
thesimonmanuel
2025-07-17 08:02:08
(11 months ago)
129.226.145.114 - - [17/Jul/2025:10:35:47 +0530] "POST /xmlrpc.php HTTP/1.1" 401 172 "-" "Mozilla/5. ...
show more
129.226.145.114 - - [17/Jul/2025:10:35:47 +0530] "POST /xmlrpc.php HTTP/1.1" 401 172 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0" "-"
129.226.145.114 - - [17/Jul/2025:10:35:57 +0530] "POST /xmlrpc.php HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36" "-"
129.226.145.114 - - [17/Jul/2025:13:32:07 +0530] "POST /xmlrpc.php HTTP/1.1" 401 172 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" "-"
show less
Brute-Force
Web App Attack