๐ฉ๐ช
Vegascosmetics
2026-06-19 14:06:08
(11 hours ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after suspicious activity. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐ฉ๐ช
4server
2026-06-19 11:31:34
(14 hours ago)
[FriJun1913:31:32.0035982026][security2:error][pid1950807:tid1950953][client163.53.176.201:0]ModSecu ...
show more
[FriJun1913:31:32.0035982026][security2:error][pid1950807:tid1950953][client163.53.176.201:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"tourkomanis.ch\"][uri\"/xmlrpc.php\"][unique_id\"ajUolG0H6h5nONlpTnP1xwAAANg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-19 10:45:03
(15 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-19 07:40:26
(18 hours ago)
Unauthorized access to webpage admin
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-18 08:37:58
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฌ๐ง
consul.to
2026-06-17 08:57:18
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
4server
2026-06-17 08:25:30
(2 days ago)
[WedJun1710:25:25.2451902026][security2:error][pid2757571:tid2757690][client163.53.176.201:0]ModSecu ...
show more
[WedJun1710:25:25.2451902026][security2:error][pid2757571:tid2757690][client163.53.176.201:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"autoeuro.lv\"][uri\"/xmlrpc.php\"][unique_id\"ajJZ9Q15ft7kdm56qlMuWQAAAAE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
rh24
2026-06-17 07:37:44
(2 days ago)
(wordpress) Failed wordpress login from 163.53.176.201 (IN/India/-): (CF_ENABLE)
Brute-Force
Anonymous
2026-06-17 06:06:10
(2 days ago)
Attac
Brute-Force
๐ณ๐ฑ
Site.eu
2026-06-17 05:00:34
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-16 12:07:05
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 163.53.176.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 163.53.176.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 08:06:59.126662 2026] [security2:error] [pid 4420:tid 4420] [client 163.53.176.201:36927] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atidysort.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atidysort.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajE8Y3JUgNwAqpm3eDdchgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 07:10:47
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 163.53.176.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 163.53.176.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 03:10:41.999017 2026] [security2:error] [pid 1462:tid 1462] [client 163.53.176.201:38660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||reyadecostarica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "reyadecostarica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajD28eSLgEk_koH9DPEmzAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 06:19:55
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 163.53.176.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 163.53.176.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 02:19:50.219260 2026] [security2:error] [pid 19691:tid 19906] [client 163.53.176.201:35341] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kettlehill.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-ZhmP9MJEDhbHGivjfuwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-06-13 06:54:24
(6 days ago)
Known malicious PHP file or CMS probe
Web App Attack
๐ณ๐ฑ
Roderic
2026-06-12 07:40:50
(1 week ago)
(apache_scanners-2) Failed apache-scanners trigger with match [redacted])
Port Scan