🇺🇸
TPI-Abuse
2026-09-05 18:32:02
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 14:31:55.487170 2026] [security2:error] [pid 14398:tid 14398] [client 192.3.26.7:42596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||riedmannfamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "riedmannfamily.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apxgGzkiDo65PYe8eUxYywAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 17:18:43
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 13:18:37.904923 2026] [security2:error] [pid 29315:tid 29315] [client 192.3.26.7:38596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sooperare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sooperare.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apxO7UMWHQeC-oGSWU8A0gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dtorrer
2026-09-05 17:16:27
(7 hours ago)
Forged login request.
Brute-Force
Anonymous
2026-09-05 16:41:32
(8 hours ago)
WordPress Brute Force
Brute-Force
Anonymous
2026-09-05 16:35:05
(8 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇩🇪
juutis
2026-09-05 16:25:50
(8 hours ago)
192.3.26.7 - - [05/Sep/2026:12:41:42 +0200] "POST /wp-login.php HTTP/1.1" 200 9617 "https://www.taid ...
show more
192.3.26.7 - - [05/Sep/2026:12:41:42 +0200] "POST /wp-login.php HTTP/1.1" 200 9617 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
192.3.26.7 - - [05/Sep/2026:14:59:11 +0200] "POST /wp-login.php HTTP/1.1" 200 9599 "https://taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
192.3.26.7 - - [05/Sep/2026:18:25:48 +0200] "POST /wp-login.php HTTP/1.1" 200 9616 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Web App Attack
🇩🇪
LRob
2026-09-05 16:04:26
(8 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-05 16:04 UTC
Brute-Force
Web App Attack
Anonymous
2026-09-05 14:23:02
(10 hours ago)
(caddyscan) Scanner path probe from 192.3.26.7 (US/United States/192-3-26-7-host.colocrossing.com): ...
show more
(caddyscan) Scanner path probe from 192.3.26.7 (US/United States/192-3-26-7-host.colocrossing.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 302 365 192.3.26.7 - - [05/Sep/2026:14:22:57 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 302 365 192.3.26.7 - - [05/Sep/2026:14:22:57 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 302 365 192.3.26.7 - - [05/Sep/2026:14:22:57 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 302 365 192.3.26.7 - - [05/Sep/2026:14:22:57 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 302 365 192.3.26.7 - - [05/Sep/2026:14:22:57 +0000] "GET /xmlrpc.php HTTP/1.1"
show less
Port Scan
🇺🇸
omc
2026-09-05 14:16:28
(10 hours ago)
Banned IP [QC]. GET /wp-sitemap-users-1.xml [Q4]. Layer 7 burst [QR].
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-09-05 13:51:34
(10 hours ago)
192.3.26.7 - - [05/Sep/2026:15:51:34 +0200] "POST /xmlrpc.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Wi ...
show more
192.3.26.7 - - [05/Sep/2026:15:51:34 +0200] "POST /xmlrpc.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 13:49:49
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 09:49:43.856788 2026] [security2:error] [pid 32690:tid 32690] [client 192.3.26.7:37782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dd214chronicle.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dd214chronicle.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apwd9zDJyvUi2L2_HbGwIgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
wordpresshosting.solutions
2026-09-05 13:43:48
(11 hours ago)
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 192.3.26.7 - - [05/Sep/2026:13: ...
show more
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 192.3.26.7 - - [05/Sep/2026:13:43:45 +0000] "GET /wp-login.php HTTP/1.1" 200 9834 "https://[DOMAIN]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
192.3.26.7 - - [05/Sep/2026:13:43:47 +0000] "GET /wp-login.php HTTP/1.1" 200 5023 "https://[DOMAIN]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 13:28:25
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 09:28:17.911308 2026] [security2:error] [pid 27955:tid 27955] [client 192.3.26.7:39656] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wild-goose.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wild-goose.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apwY8VEXZRSLdF3YIyfaLAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 12:43:13
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 192.3.26.7 (192-3-26-7-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 08:43:05.577099 2026] [security2:error] [pid 21407:tid 21407] [client 192.3.26.7:45942] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||soereng.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "soereng.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apwOWeDZoB9IqeruNnRZWQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
conseilgouz
2026-09-05 12:39:00
(12 hours ago)
hae-7 : Trying access unauthorized files/dir=>/xmlrpc.php
Hacking