Anonymous
2026-06-06 19:30:03
(6 hours ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 16:42:27
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 12:42:22.306998 2026] [security2:error] [pid 19277:tid 19277] [client 141.95.66.91:36292] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kulacenterky.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kulacenterky.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiRN7uaXE4TJ5GqicCItTwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 13:14:43
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 09:14:35.957179 2026] [security2:error] [pid 22195:tid 22195] [client 141.95.66.91:34014] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soonerstone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiQdO0lIPgQPJnUscqU3QAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-05 16:09:18
(1 day ago)
[redacted] 141.95.66.91 - - [05/Jun/2026:18:09:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 141.95.66.91 - - [05/Jun/2026:18:09:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0"
[redacted] 141.95.66.91 - - [05/Jun/2026:18:09:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0"
[redacted] 141.95.66.91 - - [05/Jun/2026:18:09:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:43.0) Gecko/20100101 Firefox/43.0"
[redacted] 141.95.66.91 - - [05/Jun/2026:18:09:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"
[redacted] 141.95.66.91 - - [05/Jun/2026:18:09:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 141.95.66.91 - -
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 16:55:26
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 12:55:19.728772 2026] [security2:error] [pid 17657:tid 17657] [client 141.95.66.91:48716] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cyqci.eu|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cyqci.eu"] [uri "/wp-json/wp/v2/users"] [unique_id "aiGt95w4D8K73zsqzxct9AAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 15:04:21
(2 days ago)
[redacted] 141.95.66.91 - - [04/Jun/2026:17:04:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 141.95.66.91 - - [04/Jun/2026:17:04:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0"
[redacted] 141.95.66.91 - - [04/Jun/2026:17:04:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:69.0) Gecko/20100101 Firefox/69.0"
[redacted] 141.95.66.91 - - [04/Jun/2026:17:04:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0"
[redacted] 141.95.66.91 - - [04/Jun/2026:17:04:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0"
[redacted] 141.95.66.91 - - [04/Jun/2026:17:04:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0"
[redacted] 141.95.66.91 - -
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 12:36:39
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 08:36:35.532059 2026] [security2:error] [pid 12405:tid 12405] [client 141.95.66.91:53468] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||modestosoftwater.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "modestosoftwater.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiFxU-9EJuUWvybiG1dCMQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 03:25:41
(2 days ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-03 13:33:20
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 09:33:13.384214 2026] [security2:error] [pid 19202:tid 19202] [client 141.95.66.91:36764] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.inquisitivequincie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.inquisitivequincie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiAtGYrTx7eZLtMwMI7DvAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 01:06:42
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 21:06:38.676461 2026] [security2:error] [pid 15155:tid 15155] [client 141.95.66.91:34006] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jdeloa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jdeloa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah9-Hrec8f0kuOMYn2iPSQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 04:15:48
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 141.95.66.91 (ns3206989.ip-141-95-66.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 00:15:40.442985 2026] [security2:error] [pid 16159:tid 16159] [client 141.95.66.91:37646] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bonnesfrequences.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bonnesfrequences.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah5Y7BzEpCIVhn01muNLeQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-04-15 03:15:18
(1 month ago)
Web attack from 141.95.66.91
Web App Attack
๐ง๐พ
lns.bz
2026-04-13 00:40:35
(1 month ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-04-11 11:40:04
(1 month ago)
Wordfence waf block on wp20190711M4
Web App Attack
๐ท๐ด
INTEQ
2026-04-11 08:17:22
(1 month ago)
Web attack from 141.95.66.91
Web App Attack