๐ซ๐ท
SpaceHost-Server
2026-06-12 22:26:04
(25 minutes ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 11:34:13
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 07:34:09.610547 2026] [security2:error] [pid 31566:tid 31566] [client 130.195.240.8:22755] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.judithcaldwell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.judithcaldwell.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aivuse47kwO4oB2P1yXLgQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-12 11:12:27
(11 hours ago)
(wordpress) Failed wordpress login from 130.195.240.8 (MD/Moldova/-)
Brute-Force
๐ฎ๐ฉ
Burayot
2026-06-12 10:56:44
(11 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 130.195.240.8 (MD/Moldova/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 130.195.240.8 (MD/Moldova/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:00:12
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:00:06.226618 2026] [security2:error] [pid 28380:tid 28380] [client 130.195.240.8:54852] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.josephshv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.josephshv.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aivKlq_PQ9MBvHfO-5corgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-12 08:45:41
(14 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-12 08:23:39
(14 hours ago)
130.195.240.8 - - [12/Jun/2026:10:23:36 +0200] "POST //xmlrpc.php HTTP/1.1" 200 591 "-" "Mozilla/5.0 ...
show more
130.195.240.8 - - [12/Jun/2026:10:23:36 +0200] "POST //xmlrpc.php HTTP/1.1" 200 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
130.195.240.8 - - [12/Jun/2026:10:23:37 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
130.195.240.8 - - [12/Jun/2026:10:23:37 +0200] "POST //xmlrpc.php HTTP/1.1" 200 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
130.195.240.8 - - [12/Jun/2026:10:23:38 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
130.195.240.8 - - [12/Jun/2026:10:23:38 +0200] "POST //xmlrpc.php HTTP/1.1" 200 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.
...
show less
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-12 08:09:05
(14 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
NZ/New Zealand/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 07:59:21
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 03:59:17.331478 2026] [security2:error] [pid 6708:tid 6708] [client 130.195.240.8:23787] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jonasrimkunas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jonasrimkunas.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiu8VU5ijA5ua--mGsGv6wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-06-12 07:54:07
(14 hours ago)
(wordpress) Failed wordpress login from 130.195.240.8 (MD/Moldova/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-12 07:41:58
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 03:41:50.652249 2026] [security2:error] [pid 16408:tid 16408] [client 130.195.240.8:4059] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiu4PoMrw88imK82rkyvdwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 07:08:25
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 03:08:18.968749 2026] [security2:error] [pid 1803:tid 1803] [client 130.195.240.8:1742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||haverhillhouse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "haverhillhouse.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiuwYhAMTkITo7zZSqeZrgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 06:44:36
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:44:29.807732 2026] [security2:error] [pid 18927:tid 18998] [client 130.195.240.8:58230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jofdt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jofdt.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiuqzWdTXFfkZgYO0TV6dQAAAcI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-06-12 06:42:42
(16 hours ago)
(xmlrpc) Failed xmlrpc access from 130.195.240.8 (MD/Moldova/-): 5 in the last 3600 secs (0-122)
Hacking
Anonymous
2026-06-12 06:39:00
(16 hours ago)
[redacted] 130.195.240.8 - - [12/Jun/2026:08:38:43 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" " ...
show more
[redacted] 130.195.240.8 - - [12/Jun/2026:08:38:43 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 130.195.240.8 - - [12/Jun/2026:08:38:45 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 130.195.240.8 - - [12/Jun/2026:08:38:47 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 130.195.240.8 - - [12/Jun/2026:08:38:48 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 130.195.240.8 - - [12/Jun/2026:08:38:50 +
...
show less
Hacking
Web App Attack