๐ฉ๐ช
LRob.fr
2026-06-17 03:15:02
(1 week ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 23:09:25
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 19:09:12.072545 2026] [security2:error] [pid 23176:tid 23176] [client 180.194.195.241:19086] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ohwaitiforgot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ohwaitiforgot.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajHXmKB0XO_gby5s06FMZgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-15 11:24:41
(1 week ago)
Unauthorized access to webpage admin
Web App Attack
๐จ๐ฆ
polycoda
2026-06-15 10:56:30
(1 week ago)
๐ Wordpress login brute force attempt
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 09:38:08
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:37:57.308350 2026] [security2:error] [pid 6131:tid 6131] [client 180.194.195.241:17783] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||palumbodesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "palumbodesigns.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_H9Uu5vXRKOm8RNbmm7QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-15 04:20:43
(1 week ago)
Try to access /xmlrpc.php
Web App Attack
๐ฎ๐ฉ
Burayot
2026-06-15 00:01:30
(1 week ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 180.194.195.241 (PH/Philippines/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 180.194.195.241 (PH/Philippines/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:53:11
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:52:59.692930 2026] [security2:error] [pid 9949:tid 9949] [client 180.194.195.241:18308] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||disio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "disio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai8-27dsBCBe1qftV4eOWgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-14 22:53:04
(1 week ago)
[MonJun1500:52:55.9757472026][security2:error][pid3364310:tid3364316][client180.194.195.241:0]ModSec ...
show more
[MonJun1500:52:55.9757472026][security2:error][pid3364310:tid3364316][client180.194.195.241:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"cst-ranghetti.ch\"][uri\"/xmlrpc.php\"][unique_id\"ai8wx8timeK0es7A4q7SEQAAAEM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 12:33:10
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 08:32:58.602134 2026] [security2:error] [pid 8834:tid 8834] [client 180.194.195.241:19203] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prostar.industries"] [uri "/wp-json/wp/v2/users"] [unique_id "ai6femJOCF738FuhCGxYVAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-14 07:30:03
(1 week ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 06:10:48
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 180.194.195.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:10:36.818783 2026] [security2:error] [pid 15338:tid 15338] [client 180.194.195.241:17442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||joeordie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "joeordie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai5F3K7BSc36QCZiOcoVTwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack