๐ฉ๐ช
Vegascosmetics
2026-06-26 16:29:54
(2 hours ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐ช๐ธ
alferez
2026-06-25 23:51:11
(19 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 13:35:45
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 143.44.192.160 (143.44.192.160-rev.convergeict. ...
show more
(mod_security) mod_security (id:225170) triggered by 143.44.192.160 (143.44.192.160-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 09:35:37.614177 2026] [security2:error] [pid 17888:tid 17888] [client 143.44.192.160:12359] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||digi-estudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "digi-estudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aj0uqWD-V9vkl6WEr6wHeAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 10:57:29
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 143.44.192.160 (143.44.192.160-rev.convergeict. ...
show more
(mod_security) mod_security (id:225170) triggered by 143.44.192.160 (143.44.192.160-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 06:57:20.646868 2026] [security2:error] [pid 19655:tid 19666] [client 143.44.192.160:61475] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leaderoftheopposition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leaderoftheopposition.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aju4ELKLoFJOz8Ff_KGS5AAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-22 14:42:30
(4 days ago)
[MonJun2216:42:26.5077932026][security2:error][pid1108353:tid1108374][client143.44.192.160:0]ModSecu ...
show more
[MonJun2216:42:26.5077932026][security2:error][pid1108353:tid1108374][client143.44.192.160:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"ticino-host.ch\"][uri\"/xmlrpc.php\"][unique_id\"ajlJ0mFswiAuJ8eCMYGkYgAAAAs\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-22 07:30:42
(4 days ago)
143.44.192.160 - - [22/Jun/2026:
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-22 07:17:28
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 143.44.192.160 (143.44.192.160-rev.convergeict. ...
show more
(mod_security) mod_security (id:225170) triggered by 143.44.192.160 (143.44.192.160-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 03:17:20.200707 2026] [security2:error] [pid 20512:tid 20512] [client 143.44.192.160:62508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||indoorsfinishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "indoorsfinishing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajjhgKpT1akL2WoOvsT9YAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-21 16:54:39
(5 days ago)
Wordpress Vunerability attack
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-20 09:21:11
(6 days ago)
Try to access /xmlrpc.php
Web App Attack
Anonymous
2026-06-20 04:08:09
(6 days ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 16:23:44
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 143.44.192.160 (143.44.192.160-rev.convergeict. ...
show more
(mod_security) mod_security (id:225170) triggered by 143.44.192.160 (143.44.192.160-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 12:23:38.712255 2026] [security2:error] [pid 29855:tid 29855] [client 143.44.192.160:9391] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tomkatkaraoke.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tomkatkaraoke.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajQbimu_EIXm0TFSci4W2QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 09:08:14
(1 week ago)
Trying to access config files
Web App Attack
๐ง๐พ
lns.bz
2026-06-17 07:50:03
(1 week ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
Anonymous
2026-06-16 13:07:46
(1 week ago)
Trying to access config files
Web App Attack
Anonymous
2026-06-15 13:32:08
(1 week ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack