Anonymous
2026-06-22 20:27:43
(20 hours ago)
[redacted] 179.41.7.254 - - [22/Jun/2026:22:27:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 179.41.7.254 - - [22/Jun/2026:22:27:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
[redacted] 179.41.7.254 - - [22/Jun/2026:22:27:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0"
[redacted] 179.41.7.254 - - [22/Jun/2026:22:27:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0"
[redacted] 179.41.7.254 - - [22/Jun/2026:22:27:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:43.0) Gecko/20100101 Firefox/43.0"
[redacted] 179.41.7.254 - - [22/Jun/2026:22:27:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
[redacted] 179.41.7.254 - - [22/Jun/202
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 18:06:04
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 14:05:57.447920 2026] [security2:error] [pid 27715:tid 27715] [client 179.41.7.254:35472] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.haverhillhouse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.haverhillhouse.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajl5hRpQKan3CtpITRkYUQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 11:13:18
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 07:13:11.322563 2026] [security2:error] [pid 23169:tid 23169] [client 179.41.7.254:42974] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||williamfitzsimmons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "williamfitzsimmons.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkYx-de3g6KL2MVMfEtAAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-06-22 10:57:26
(1 day ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-22 04:50:43
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 00:50:37.021374 2026] [security2:error] [pid 25559:tid 25559] [client 179.41.7.254:46202] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lambert-heating-and-air.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aji_HYu9naUztjmiH_4fngAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 03:05:22
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 23:05:17.018279 2026] [security2:error] [pid 723:tid 723] [client 179.41.7.254:46338] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bickleton.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajimbaoi_Wbggie0KdF29AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 00:45:30
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 20:45:24.809239 2026] [security2:error] [pid 22970:tid 22970] [client 179.41.7.254:58788] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.d-sinema.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajiFpFTJXOys1vVlFW0nWgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 21:52:13
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 17:52:08.816852 2026] [security2:error] [pid 15290:tid 15290] [client 179.41.7.254:58096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marinestorage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marinestorage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajhdCICQbzpRvOIpB_aIxgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
reznekcs
2026-06-21 13:36:55
(2 days ago)
F2B wordpress ban. Logs: 179.41.7.254 - - [21/Jun/2026:15:36:54 +0200] "POST /xmlrpc.php HTTP/1.1" 2 ...
show more
F2B wordpress ban. Logs: 179.41.7.254 - - [21/Jun/2026:15:36:54 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0"
179.41.7.254 - - [21/Jun/2026:15:36:54 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:63.0) Gecko/20100101 Firefox/63.0"
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 09:42:26
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 05:42:20.877275 2026] [security2:error] [pid 29500:tid 29500] [client 179.41.7.254:36678] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||opticasprisma.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "opticasprisma.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajex_Lquo03PehkHGmYrjQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 04:45:50
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 00:45:46.354603 2026] [security2:error] [pid 2206:tid 2206] [client 179.41.7.254:33526] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.indiahouseportland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.indiahouseportland.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdseidy-OifS008VyB52gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 03:08:38
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 23:08:31.068708 2026] [security2:error] [pid 32176:tid 32176] [client 179.41.7.254:46904] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.silalaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.silalaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdVrz0ai0rXcXLBsO_OswAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 23:54:30
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 19:54:25.383908 2026] [security2:error] [pid 5098:tid 5098] [client 179.41.7.254:36648] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "johncyphers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajcoMcGflSN6U7NvoBQVYAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 22:18:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 18:18:41.839735 2026] [security2:error] [pid 6067:tid 6067] [client 179.41.7.254:39558] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "major33.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajcRwRJ91XFZpqHA-1gf2wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-20 22:02:49
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 179.41.7.254 (179-41-7-254.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 18:02:44.113787 2026] [security2:error] [pid 6031:tid 6031] [client 179.41.7.254:56564] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lightbender.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lightbender.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajcOBE0F6Iw8YrQfPBqSOwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack