๐ฉ๐ช
LRob
2026-08-16 12:41:19
(1 week ago)
WordPress probing | req: /xmlrpc.php | UA: PHP/5.2.61
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-08-13 02:26:33
(2 weeks ago)
IM360 WAF: WordPress wp2shell REST batch endpoint via POST-body rest_route before 7.0.2 or 6.9.5 (CV ...
show more
IM360 WAF: WordPress wp2shell REST batch endpoint via POST-body rest_route before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:1
show less
Hacking
๐ฎ๐น
Catapult
2026-08-09 06:01:00
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-02 07:16:37
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 03:16:30.773655 2026] [security2:error] [pid 1207628:tid 1207652] [client 178.20.215.252:40995] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lauricella.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lauricella.us"] [uri "/wp-json/wp/v2/users"] [unique_id "am7uzjr1xfxMFbw2hMFaZQAAAFU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-28 09:27:00
(4 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 01:22:22
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 21:22:17.066770 2026] [security2:error] [pid 3803662:tid 3803662] [client 178.20.215.252:21429] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||limbertree.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "limbertree.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amayyYnZTcjgMpgAVqm0dQAAABg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 21:15:54
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 17:15:48.687578 2026] [security2:error] [pid 2113505:tid 2113505] [client 178.20.215.252:18087] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desimon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desimon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al0-hH4iTs8HAUpkx7Q7_wAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-07-18 21:03:36
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 15:28:24
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 11:28:17.181396 2026] [security2:error] [pid 8999:tid 8999] [client 178.20.215.252:42953] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||areafinancieratf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "areafinancieratf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alUEEb_yI_uTsUaP_MGjHgAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-26 00:16:36
(2 months ago)
[Fri Jun 26 10:16:35.756418 2026] [security2:error] [pid 594151] [client 178.20.215.252:46895] [clie ...
show more
[Fri Jun 26 10:16:35.756418 2026] [security2:error] [pid 594151] [client 178.20.215.252:46895] [client 178.20.215.252] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/xmlrpc.php"] [unique_id "aj3E42G0do7iHO2eqBzU5wAAAA0"]
...
show less
Web App Attack
Anonymous
2026-05-28 20:24:11
(2 months ago)
SQL injection, multiple attempts.
SQL Injection
Anonymous
2026-05-18 21:51:40
(3 months ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 17:28:21
(3 months ago)
(mod_security) mod_security (id:218580) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 178.20.215.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 13:28:18.392136 2026] [security2:error] [pid 25820:tid 25820] [client 178.20.215.252:63023] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:netId. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||3905ccn.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "3905ccn.org"] [uri "/maintNetInstance.php"] [unique_id "agipMuZg-pnrdOqSU105-wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
Detmach
2026-04-13 07:26:44
(4 months ago)
Security attack detected. Multiple failed attempts from 178.20.215.252. IP banned for 1440 minutes a ...
show more
Security attack detected. Multiple failed attempts from 178.20.215.252. IP banned for 1440 minutes at 13.04.2026 10:26:00. Failed attempts: 1
show less
Brute-Force
Anonymous
2025-03-12 15:11:09
(1 year ago)
Brute Force attempts
Brute-Force
Exploited Host