๐ฉ๐ช
webanyone
2026-07-21 17:00:53
(3 hours ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-21 15:15:39
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 165.227.79.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.227.79.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 11:15:32.279446 2026] [security2:error] [pid 4866:tid 4866] [client 165.227.79.236:53784] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zoesaadeh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zoesaadeh.com"] [uri "/zoe-saadeh/wp-json/wp/v2/users/"] [unique_id "al-NFPk7Mk70eP2QSeZNfQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-07-21 14:29:55
(5 hours ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 13:32:23
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 165.227.79.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.227.79.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 09:32:15.818035 2026] [security2:error] [pid 26415:tid 26415] [client 165.227.79.236:59542] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.zezel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.zezel.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al9039AUCC_vYfIJIFySbQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-21 13:11:13
(6 hours ago)
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 165.227.79.236 - - [21/Jul/2026:16:11:13 +0300] "G ...
show more
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 165.227.79.236 - - [21/Jul/2026:16:11:13 +0300] "GET //xmlrpc.php?rsd HTTP/1.1" 404 3960 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Web App Attack
๐ฎ๐ฉ
zam
2026-07-21 11:49:51
(8 hours ago)
165.227.79.236 - - [21/Jul/2026:11:49:50 +0000] "POST //xmlrpc.php HTTP/1.1" 403 239
Web App Attack
๐ฌ๐ง
Oakley
2026-07-21 11:21:57
(8 hours ago)
(mod_security) mod_security (id:900191) triggered by 165.227.79.236 (US/United States/-): 5 in the l ...
show more
(mod_security) mod_security (id:900191) triggered by 165.227.79.236 (US/United States/-): 5 in the last 900 secs
show less
Web App Attack
Hacking
๐น๐ท
ycoskun41
2026-07-21 10:08:06
(9 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ฌ๐ง
Yosi
2026-07-21 09:18:15
(10 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
mnsf
2026-07-21 09:05:09
(11 hours ago)
Abuse Detected (13)
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-07-21 09:04:19
(11 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 165.227.79.236 (US/United States/-): 1 in the ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 165.227.79.236 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 165.227.79.236 - - [21/Jul/2026:11:04:15 +0200] "GET //wp-json/wp/v2/users/ HTTP/2.0" 200 2021 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" "165.227.79.236" host=www.yogiraji.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-21 09:04:07
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 165.227.79.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 165.227.79.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 05:03:59.359173 2026] [security2:error] [pid 3269:tid 3269] [client 165.227.79.236:59153] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.yogawithbubba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.yogawithbubba.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al81_1J3hYwt6fdb_vq8JQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
YF
2026-07-21 08:30:29
(11 hours ago)
WordPress directory enumeration
Web App Attack
Anonymous
2026-07-21 08:08:04
(11 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-07-21 07:55:05
(12 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack