๐ช๐ธ
masterguru
2026-06-23 04:10:10
(2 hours ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-22 22:27:23
(8 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 21:16:54
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 17:16:50.049390 2026] [security2:error] [pid 15688:tid 15688] [client 15.235.224.64:37344] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.arthuryeung.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.arthuryeung.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajmmQh-ojZ4OXqMcNI2uzQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 19:39:00
(11 hours ago)
[ns41.kdns.gr] httpd-suspicious-path: sites=apnoia.gr; logs=/var/log/httpd/domains/apnoia.gr.log; sa ...
show more
[ns41.kdns.gr] httpd-suspicious-path: sites=apnoia.gr; logs=/var/log/httpd/domains/apnoia.gr.log; samples=/wp-json/wp/v2/users | /?author=1 | /?author=2
show less
Hacking
Web App Attack
Anonymous
2026-06-22 18:23:48
(12 hours ago)
15.235.224.64 - - > www.allacasadilucia.it [22/Jun/2026:20:23:47 +0200] "POST /xmlrpc.php HTTP/1.1" ...
show more
15.235.224.64 - - > www.allacasadilucia.it [22/Jun/2026:20:23:47 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0" "-"
15.235.224.64 - - > www.allacasadilucia.it [22/Jun/2026:20:23:47 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0" "-"
15.235.224.64 - - > www.allacasadilucia.it [22/Jun/2026:20:23:47 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-"
15.235.224.64 - - > www.allacasadilucia.it [22/Jun/2026:20:23:47 +0200] "POST /wp-login.php HTTP/1.1" 200 2438 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0" "-"
15.235.224.64 - - > www.allacasadilucia.it [22/Jun/2026:20:23:47 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" "-"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Rexikon
2026-06-22 07:22:56
(23 hours ago)
15.235.224.64 - - [22/Jun/2026:09:22:52 +0200] "POST /wp-login.php HTTP/1.1" 200 16380 "-" "Mozilla/ ...
show more
15.235.224.64 - - [22/Jun/2026:09:22:52 +0200] "POST /wp-login.php HTTP/1.1" 200 16380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:50.0) Gecko/20100101 Firefox/50.0"
15.235.224.64 - - [22/Jun/2026:09:22:55 +0200] "POST /wp-login.php HTTP/1.1" 200 16376 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0"
15.235.224.64 - - [22/Jun/2026:09:22:55 +0200] "POST /wp-login.php HTTP/1.1" 200 16376 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:69.0) Gecko/20100101 Firefox/69.0"
15.235.224.64 - - [22/Jun/2026:09:22:55 +0200] "POST /wp-login.php HTTP/1.1" 200 16376 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0"
15.235.224.64 - - [22/Jun/2026:09:22:55 +0200] "POST /wp-login.php HTTP/1.1" 200 16376 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-21 02:48:22
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 22:48:17.588657 2026] [security2:error] [pid 28694:tid 28694] [client 15.235.224.64:42782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.graymatterofdc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.graymatterofdc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdQ8Sske7aDtgEPmO0YUwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 22:46:29
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 18:46:23.522045 2026] [security2:error] [pid 22320:tid 22320] [client 15.235.224.64:40802] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.truthsabouthealthcare.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajcYPwLc8PdsyRjMTbyMtwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 08:50:09
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 04:49:59.171208 2026] [security2:error] [pid 6353:tid 6353] [client 15.235.224.64:33742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.xhumanlikerobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.xhumanlikerobots.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajZUN01ha77p2IlgJWatDAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 00:25:17
(3 days ago)
[redacted] 15.235.224.64 - - [20/Jun/2026:02:25:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "M ...
show more
[redacted] 15.235.224.64 - - [20/Jun/2026:02:25:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0"
[redacted] 15.235.224.64 - - [20/Jun/2026:02:25:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
[redacted] 15.235.224.64 - - [20/Jun/2026:02:25:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0"
[redacted] 15.235.224.64 - - [20/Jun/2026:02:25:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0"
[redacted] 15.235.224.64 - - [20/Jun/2026:02:25:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0"
[redacted] 15.235.224.64 - - [20/Jun/2026:02:25:12 +0200] "POST
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 05:42:17
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 01:42:12.468931 2026] [security2:error] [pid 23796:tid 23796] [client 15.235.224.64:54384] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.badconsultingllc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.badconsultingllc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajTWtEcthvd0xRXtK11GVwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-19 04:28:45
(4 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 18:07:14
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 14:07:07.168897 2026] [security2:error] [pid 16698:tid 16698] [client 15.235.224.64:52272] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.smilingorc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.smilingorc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajGQy3AfmPPx0f5vkllvtAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 05:51:07
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 15.235.224.64 (ns5031371.ip-15-235-224.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 01:51:03.886888 2026] [security2:error] [pid 23868:tid 23868] [client 15.235.224.64:36786] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lajoze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lajoze.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajDkR11saWHTXPL6ekcE_AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-15 22:26:49
(1 week ago)
Brute-Force
Web App Attack