๐ฆ๐บ
screwlooseit.com.au
2026-06-07 18:20:34
(5 hours ago)
Blocked by CSF 13 firewall - Rule: DE/Germany/rock2.plmis.com
Web App Attack
Anonymous
2026-06-07 16:37:03
(6 hours ago)
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /wp-json/wp/v2/users HTTP/1.1, GET /auth ...
show more
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /wp-json/wp/v2/users HTTP/1.1, GET /author/admin/ HTTP/1.1, GET /?author=2 HTTP/1.1, POST /xmlrpc.php HTTP/1.1, GET /?author=1 HTTP/1.1, POST /wp-login.php HTTP/1.1, GET /?author=3 HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 19:20:07
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 15:20:00.119187 2026] [security2:error] [pid 7200:tid 7211] [client 176.9.47.205:33072] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.plumeraproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.plumeraproductions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiRy4Bw3RWXWZjuOA31PUQAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 18:37:24
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 14:37:18.758948 2026] [security2:error] [pid 24420:tid 24420] [client 176.9.47.205:58726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soonerstone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiRo3i49wtWs3E3uzTOmfgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 18:18:47
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 14:18:42.131797 2026] [security2:error] [pid 20738:tid 20738] [client 176.9.47.205:56854] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ironsightsarmory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ironsightsarmory.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiMTAuBv6cNEOLUAG_rdbQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 16:19:16
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 12:19:10.242327 2026] [security2:error] [pid 27670:tid 27670] [client 176.9.47.205:44120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.thefrontporchoffering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.thefrontporchoffering.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahxffsmAWHZ7udraFB2VdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 07:46:30
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 03:46:23.755174 2026] [security2:error] [pid 30605:tid 30605] [client 176.9.47.205:51630] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.randymcelroy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.randymcelroy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahvnT3p7leNYr0rQN1JKHgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 11:04:16
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 07:04:12.552078 2026] [security2:error] [pid 8274:tid 8274] [client 176.9.47.205:43144] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.arthuryeung.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.arthuryeung.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ahrELB1btZ4g2ApDUffOfQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-05-30 04:00:04
(1 week ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-05-30 03:18:02
(1 week ago)
Probing for Exploits on ns74
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 22:15:07
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 18:14:59.569890 2026] [security2:error] [pid 6034:tid 6034] [client 176.9.47.205:46322] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kobraagencies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kobraagencies.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahoP4zAXHepbX8RRpxbQRgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-29 13:58:51
(1 week ago)
[redacted] 176.9.47.205 - - [29/May/2026:15:58:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 176.9.47.205 - - [29/May/2026:15:58:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:41.0) Gecko/20100101 Firefox/41.0"
[redacted] 176.9.47.205 - - [29/May/2026:15:58:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
[redacted] 176.9.47.205 - - [29/May/2026:15:58:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0"
[redacted] 176.9.47.205 - - [29/May/2026:15:58:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:44.0) Gecko/20100101 Firefox/44.0"
[redacted] 176.9.47.205 - - [29/May/2026:15:58:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 176.9.47.205 - - [29/May/202
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 00:06:33
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 20:06:28.757806 2026] [security2:error] [pid 10604:tid 10604] [client 176.9.47.205:59152] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tedharris.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahjYhCkvcMGTsWHTksWXTwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 16:49:41
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 12:49:33.867458 2026] [security2:error] [pid 8070:tid 8070] [client 176.9.47.205:34814] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fgrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fgrotary.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ahhyHR-DJvTpRgwizbqD4wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 01:47:52
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 176.9.47.205 (rock2.plmis.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 21:47:45.038571 2026] [security2:error] [pid 24913:tid 24913] [client 176.9.47.205:49570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.infinityartistsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.infinityartistsgroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahZNQTucsKyxaJxrPL1XeQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack