๐บ๐ธ
TPI-Abuse
2026-06-08 12:08:10
(12 minutes ago)
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 08:08:04.853290 2026] [security2:error] [pid 14971:tid 14971] [client 137.184.76.185:46114] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.susanleeward.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.susanleeward.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiawpEAzyzW29XDHrQzIUwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-08 06:43:27
(5 hours ago)
Blocked by CSF 13 firewall - Rule: US/United States/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 04:20:00
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 00:19:53.905448 2026] [security2:error] [pid 32589:tid 32589] [client 137.184.76.185:37304] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.photosatthebeach.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.photosatthebeach.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiZC6eEnCoSM_KaQbiHeXQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-08 00:00:57
(12 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 19:45:18
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 15:45:14.435522 2026] [security2:error] [pid 31859:tid 31873] [client 137.184.76.185:48478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.campingcosmetics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.campingcosmetics.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiXKSkUn0-DnPIX6WSwbmwAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-06-07 15:11:22
(21 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
bigwavedave
2026-06-07 14:25:40
(21 hours ago)
Wordpress Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 13:20:55
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 09:20:50.691301 2026] [security2:error] [pid 21750:tid 21750] [client 137.184.76.185:36350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.furbabieslivesmatter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.furbabieslivesmatter.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiVwMr36PL42vQ785uMGJgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 08:38:33
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 04:38:25.842998 2026] [security2:error] [pid 7346:tid 7346] [client 137.184.76.185:40552] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ironsightsarmory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ironsightsarmory.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiUuAUk1Wxe52yneRTooCgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 05:24:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 137.184.76.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 01:24:02.818397 2026] [security2:error] [pid 4973:tid 4973] [client 137.184.76.185:37858] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.esysapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.esysapps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiUAckBcjDtTB0AxX1F2egAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-06 19:15:51
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-06-06 15:11:24
(1 day ago)
[redacted] 137.184.76.185 - - [06/Jun/2026:17:11:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" " ...
show more
[redacted] 137.184.76.185 - - [06/Jun/2026:17:11:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0"
[redacted] 137.184.76.185 - - [06/Jun/2026:17:11:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:41.0) Gecko/20100101 Firefox/41.0"
[redacted] 137.184.76.185 - - [06/Jun/2026:17:11:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:44.0) Gecko/20100101 Firefox/44.0"
[redacted] 137.184.76.185 - - [06/Jun/2026:17:11:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0"
[redacted] 137.184.76.185 - - [06/Jun/2026:17:11:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
apoll
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-05 18:08:35
(2 days ago)
10 attempts against mh_ha-misc-ban on plum
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-05 16:56:18
(2 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-06-05 14:44:20
(2 days ago)
137.184.76.185 - - [05/Jun/2026:16:44:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 ...
show more
137.184.76.185 - - [05/Jun/2026:16:44:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0"
137.184.76.185 - - [05/Jun/2026:16:44:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0"
137.184.76.185 - - [05/Jun/2026:16:44:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0"
137.184.76.185 - - [05/Jun/2026:16:44:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0"
137.184.76.185 - - [05/Jun/2026:16:44:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0"
...
show less
Brute-Force
Web App Attack