🇩🇪
4server
2026-09-11 01:05:18
(2 days ago)
[FriSep1103:05:13.2133812026][security2:error][pid1030862:tid1030872][client185.102.113.123:0]ModSec ...
show more
[FriSep1103:05:13.2133812026][security2:error][pid1030862:tid1030872][client185.102.113.123:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"www.restaurantgandria.ch\"][uri\"/xmlrpc.php\"][unique_id\"aqNTyQ0qe6038LBsI2h9UwAAAAM\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-05 04:29:50
(1 week ago)
WordPress login attempt
Brute-Force
🇺🇸
nationaleventpros.com
2026-09-03 05:41:37
(1 week ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-08-25 01:27:03
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 21:26:55.158743 2026] [security2:error] [pid 12196:tid 12196] [client 185.102.113.123:9205] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abbysue.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abbysue.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aozvX9pCsq3pNhEBmFJyxwAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-24 18:16:40
(2 weeks ago)
Web password guessing
Brute-Force
🇬🇧
gigatech
2026-08-24 18:00:45
(2 weeks ago)
Webserver Probing
Web App Attack
🇺🇸
nationaleventpros.com
2026-08-20 17:23:38
(3 weeks ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-08-19 18:19:44
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 14:19:39.287465 2026] [security2:error] [pid 2149:tid 2149] [client 185.102.113.123:9771] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zodiacwin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zodiacwin.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoXzu0zieKKjcxLg5cMaYgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 05:00:51
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 01:00:47.173655 2026] [security2:error] [pid 28976:tid 28976] [client 185.102.113.123:61545] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||corstratinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "corstratinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoPm_zJZnWkcp5HuK9qtZgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-17 18:55:03
(3 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 17:58:22
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 13:58:16.964225 2026] [security2:error] [pid 32282:tid 32282] [client 185.102.113.123:42137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mcwyo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mcwyo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoNLuM2zFiihJ-TE2O4cCQAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-13 10:10:03
(4 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-08-11 14:10:03
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 19:58:55
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.102.113.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 15:58:46.981669 2026] [security2:error] [pid 2013572:tid 2013631] [client 185.102.113.123:56077] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woofnrose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woofnrose.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anJEdi0pn9-0rtISq6ExNgAAAFM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-03 16:39:01
(1 month ago)
Web password guessing
Brute-Force