🇫🇷
dynamix
2026-09-08 08:00:08
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:47:04
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:46:59.691657 2026] [security2:error] [pid 6432:tid 6432] [client 178.94.161.29:7062] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||ehrlichfamily.com|F|4"] [data "GET http://ehrlichfamily.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ehrlichfamily.com"] [uri "/"] [unique_id "ap-hUxnMOtOgSKcrV_buFwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:02:40
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:02:34.489125 2026] [security2:error] [pid 16335:tid 16335] [client 178.94.161.29:39001] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||wizind.com|F|4"] [data "GET http://wizind.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wizind.com"] [uri "/"] [unique_id "ap-I2m-DpjTUMV7kDI01UQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-09-08 02:03:28
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 00:11:07
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:11:02.112985 2026] [security2:error] [pid 30621:tid 30621] [client 178.94.161.29:53399] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ritterlien.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ritterlien.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap9SlqZxhIe7ekWTBMjhLwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
John Chrys.
2026-09-07 23:12:17
(2 days ago)
178.94.161.29 - - [08/Sep/2026:02:11:58 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 ...
show more
178.94.161.29 - - [08/Sep/2026:02:11:58 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0"
178.94.161.29 - - [08/Sep/2026:02:12:08 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
178.94.161.29 - - [08/Sep/2026:02:12:08 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
178.94.161.29 - - [08/Sep/2026:02:12:09 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
178.94.161.29 - - [08/Sep/2026:02:12:10 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Edg/119.0.0.0"
178.94.161.2
...
show less
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-07 23:00:05
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 15:17:56
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:17:52.289635 2026] [security2:error] [pid 2339:tid 2339] [client 178.94.161.29:43148] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||rimbey.us|F|4"] [data "GET http://rimbey.us HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rimbey.us"] [uri "/"] [unique_id "ap7VoIDBnpFFI0suDXpT5gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 14:59:58
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 178.94.161.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:59:53.980409 2026] [security2:error] [pid 20290:tid 20290] [client 178.94.161.29:56778] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||astrology7.com|F|4"] [data "ET http://astrology7.com/robots.txt HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "astrology7.com"] [uri "/robots.txt"] [unique_id "ap7RaZgPY8pTAC9xUiLOBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
masterguru
2026-09-07 13:02:45
(2 days ago)
(0-169)
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 12:26:41
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-open-proxy
Web App Attack