๐บ๐ธ
TPI-Abuse
2026-06-15 10:27:41
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 06:27:35.247148 2026] [security2:error] [pid 12781:tid 12781] [client 144.76.67.178:33882] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bosdkbook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bosdkbook.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_Tl9bqm813MEPZB1mZdwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 09:53:18
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:53:11.037939 2026] [security2:error] [pid 23309:tid 23458] [client 144.76.67.178:46348] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.metropaint.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.metropaint.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_LhwnWmXc2Gd5Jq-_BtgAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 06:24:40
(6 hours ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-15 05:11:58
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:11:53.938471 2026] [security2:error] [pid 21327:tid 21327] [client 144.76.67.178:58150] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.67ronin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.67ronin.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-JmcZYaFi7_vUfVAIqPgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:37:48
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:37:41.418211 2026] [security2:error] [pid 14431:tid 14431] [client 144.76.67.178:38588] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.peacecampus.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.peacecampus.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-BldqC_ruy4lJhZQX7wwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-14 22:26:24
(14 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 16:03:45
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 12:03:38.983607 2026] [security2:error] [pid 15014:tid 15014] [client 144.76.67.178:54712] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.intrinsicdiscovery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.intrinsicdiscovery.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai7Q2jZj6PcVMbit2pzUCQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rsiddall
2026-06-14 08:56:19
(1 day ago)
144.76.67.178 - - [14/Jun/2026:04:56:18 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 ...
show more
144.76.67.178 - - [14/Jun/2026:04:56:18 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:44.0) Gecko/20100101 Firefox/44.0"
144.76.67.178 - - [14/Jun/2026:04:56:18 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 01:51:46
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 21:51:41.673249 2026] [security2:error] [pid 32621:tid 32621] [client 144.76.67.178:46170] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adona.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adona.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai4JLQhmOsSYGymdc-X36AAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-12 12:10:14
(3 days ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐จ๐ฆ
Dolphi
2026-06-12 12:00:02
(3 days ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 07:48:40
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 03:48:32.467145 2026] [security2:error] [pid 21707:tid 21707] [client 144.76.67.178:58742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.maffiniandbearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.maffiniandbearce.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiu50PUlFG9FvzFeRYNWegAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 05:09:21
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 01:09:15.593488 2026] [security2:error] [pid 11789:tid 11814] [client 144.76.67.178:52138] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sallykimmel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sallykimmel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiuUe6hHJpmT4MeDSa3XegAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 21:39:38
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 144.76.67.178 (adrirodrigoagencia.zoroboak.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 17:39:32.806705 2026] [security2:error] [pid 19095:tid 19095] [client 144.76.67.178:51044] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ussthresher.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ussthresher.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aisrFAGb-RDiInj97K4ylgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 17:46:22
(3 days ago)
[redacted] 144.76.67.178 - - [11/Jun/2026:19:46:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "M ...
show more
[redacted] 144.76.67.178 - - [11/Jun/2026:19:46:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0"
[redacted] 144.76.67.178 - - [11/Jun/2026:19:46:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
[redacted] 144.76.67.178 - - [11/Jun/2026:19:46:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0"
[redacted] 144.76.67.178 - - [11/Jun/2026:19:46:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0"
[redacted] 144.76.67.178 - - [11/Jun/2026:19:46:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0"
...
show less
Hacking
Web App Attack