๐บ๐ธ
TPI-Abuse
2026-06-10 01:36:51
(6 minutes ago)
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 21:36:47.337508 2026] [security2:error] [pid 8978:tid 8978] [client 192.210.239.16:53876] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||earthtwoworkshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "earthtwoworkshop.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aii_rxUhMbINuts67_XuDgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 23:45:05
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 19:44:57.141930 2026] [security2:error] [pid 25947:tid 25947] [client 192.210.239.16:50936] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cliniquecavalancia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cliniquecavalancia.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiileejdeCmJZ7jsZg-iGgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tecnicorioja
2026-06-09 22:00:16
(3 hours ago)
POST /xmlrpc.php [09/Jun/2026:15:22:10
Brute-Force
Web App Attack
Anonymous
2026-06-09 20:59:04
(4 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/2.0, [1/1] done
Hacking
Web App Attack
๐ฉ๐ช
london2038.com
2026-06-09 20:10:15
(5 hours ago)
Probing for exploits
192.210.239.16 - - [09/Jun/2026:22:10:11 +0200] "GET /wp-login.php HTTP/2.0" 30 ...
show more
Probing for exploits
192.210.239.16 - - [09/Jun/2026:22:10:11 +0200] "GET /wp-login.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
192.210.239.16 - - [09/Jun/2026:22:10:12 +0200] "POST /wp-login.php HTTP/2.0" 301 0 "https://v97746.<REDACTED>/wp-login.php" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 20:05:12
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 16:05:06.610320 2026] [security2:error] [pid 6210:tid 6210] [client 192.210.239.16:41218] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nearfieldchrist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nearfieldchrist.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aihx8rpcm1wKLZOlQaCUQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-06-09 19:34:20
(6 hours ago)
192.210.239.16 - - [09/Jun/2026:13:34:19 -0600] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 ...
show more
192.210.239.16 - - [09/Jun/2026:13:34:19 -0600] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
...
show less
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-09 19:30:09
(6 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 19:16:00
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 15:15:56.459098 2026] [security2:error] [pid 12016:tid 12016] [client 192.210.239.16:58306] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theroyalhouseofelohim.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theroyalhouseofelohim.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aihmbITWeLa-DEGwYpQjKQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 18:09:04
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 192.210.239.16 (warren.help): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 14:08:59.435052 2026] [security2:error] [pid 5015:tid 5015] [client 192.210.239.16:42814] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oakvillenaturopathicclinic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oakvillenaturopathicclinic.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aihWu0byV8lpkPG7CfwQnAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
bmino.pl
2026-06-09 17:45:05
(7 hours ago)
Autoban IP(2): 192.210.239.16 - Hostname: HostPapa - City: Elk Grove Village - Region: Illinois - Co ...
show more
Autoban IP(2): 192.210.239.16 - Hostname: HostPapa - City: Elk Grove Village - Region: Illinois - Country: United States - Location: - Organization: AS36352 HostPapa - failed attempts.
show less
Web App Attack
๐บ๐ธ
nyt
2026-06-09 17:36:00
(8 hours ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-09 17:05:32
(8 hours ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-06-09 17:05:01
(8 hours ago)
2026/06/09 17:00:40 "GET /wp-login.php HTTP/2.0"
Web App Attack
๐ง๐ช
cmbplf
2026-06-09 17:00:39
(8 hours ago)
6.576 requests to many distinct domains in 1 hour (5d21h3m)
Brute-Force
Bad Web Bot