๐ฆ๐บ
screwlooseit.com.au
2026-06-07 00:33:46
(4 minutes ago)
Blocked by CSF 13 firewall - Rule: US/United States/-
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-07 00:25:22
(13 minutes ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
SpaceHost-Server
2026-06-06 22:26:24
(2 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
itsolon
2026-06-06 21:20:07
(3 hours ago)
167.172.153.2 - - [06/Jun/2026:23:20:05 +0200] "POST /wp-login.php HTTP/1.1" 200 3721 "-" "Mozilla/5 ...
show more
167.172.153.2 - - [06/Jun/2026:23:20:05 +0200] "POST /wp-login.php HTTP/1.1" 200 3721 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:43.0) Gecko/20100101 Firefox/43.0"
167.172.153.2 - - [06/Jun/2026:23:20:05 +0200] "POST /wp-login.php HTTP/1.1" 200 3721 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0"
167.172.153.2 - - [06/Jun/2026:23:20:06 +0200] "POST /wp-login.php HTTP/1.1" 200 3722 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0"
167.172.153.2 - - [06/Jun/2026:23:20:06 +0200] "POST /wp-login.php HTTP/1.1" 200 3720 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0"
167.172.153.2 - - [06/Jun/2026:23:20:06 +0200] "POST /wp-login.php HTTP/1.1" 200 3720 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 13:48:53
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 09:48:50.036929 2026] [security2:error] [pid 14937:tid 14947] [client 167.172.153.2:34508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daraluz.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daraluz.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aiQlQqPIet7xCPMdxjoy3gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 10:46:47
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 06:46:43.192452 2026] [security2:error] [pid 16726:tid 16726] [client 167.172.153.2:52816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||imbrasacademic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "imbrasacademic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiP6k-5Tr9AfyCBdZ_cJcQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-05 23:12:55
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 16:29:51
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 12:29:47.927118 2026] [security2:error] [pid 11584:tid 11584] [client 167.172.153.2:50792] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.feministvoice.blog|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.feministvoice.blog"] [uri "/wp-json/wp/v2/users"] [unique_id "aiL5e0--38DJqj5cqIu03QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-05 16:20:37
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-05 14:48:39
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:48:32.804224 2026] [security2:error] [pid 29451:tid 29451] [client 167.172.153.2:36012] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stellabluesales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stellabluesales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiLhwDrzgN7PTc87mXGP_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 17:54:04
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 13:53:59.584993 2026] [security2:error] [pid 22757:tid 22757] [client 167.172.153.2:58722] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.georgegourmet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.georgegourmet.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiG7t6GOSqm42m2O9lx7cwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 17:18:23
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 13:18:18.526579 2026] [security2:error] [pid 27086:tid 27086] [client 167.172.153.2:46728] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.enjoymycondos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.enjoymycondos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiGzWiTHjr74hsdsmD75NwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-06-04 04:55:11
(2 days ago)
(wordpress) Failed wordpress login from 167.172.153.2 (US/United States/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 00:07:19
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.172.153.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 20:07:15.088671 2026] [security2:error] [pid 31315:tid 31315] [client 167.172.153.2:46492] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.inquisitivequincie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.inquisitivequincie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiDBs33UBVrV_kHN5RgmVAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tecnicorioja
2026-06-02 22:00:10
(4 days ago)
POST /xmlrpc.php [02/Jun/2026:07:23:08
Brute-Force
Web App Attack