๐บ๐ธ
nationaleventpros.com
2026-09-03 02:10:42
(2 hours ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 23:23:36
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:23:32.496857 2026] [security2:error] [pid 25429:tid 25429] [client 193.202.12.18:37087] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wiknwax.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wiknwax.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apIYdNYmByG9_w1GNM9mTAAAADA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-17 23:37:32
(2 weeks ago)
CADANECOM WEBEXPLOIT 193.202.12.18 (193.202.12.18)
Web App Attack
Anonymous
2026-08-11 04:02:36
(3 weeks ago)
FPROCO WEBEXPLOIT 193.202.12.18 (193.202.12.18)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 08:00:06
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 03:59:58.803796 2026] [security2:error] [pid 104021:tid 104021] [client 193.202.12.18:52355] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||televisonic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "televisonic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anmE_iTwO-DNmPtQqlRDFQAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 12:06:32
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:06:28.257458 2026] [security2:error] [pid 4193057:tid 4193057] [client 193.202.12.18:16967] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dietzengineers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dietzengineers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amdJxDcPTDz3fncnXsNLpAAAABo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-28 08:33:11
(2 months ago)
Fail2Ban banned 193.202.12.18 for security violations in jail wp-armour. Log: 2026/06/28 08:33:10 [e ...
show more
Fail2Ban banned 193.202.12.18 for security violations in jail wp-armour. Log: 2026/06/28 08:33:10 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 193.202.12.18 | Target: wplogin" , client: 193.202.12.18, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
Tilellit.PRO
2026-06-27 10:17:36
(2 months ago)
Fail2Ban banned 193.202.12.18 for security violations in jail wp-armour. Log: 2026/06/27 10:17:35 [e ...
show more
Fail2Ban banned 193.202.12.18 for security violations in jail wp-armour. Log: 2026/06/27 10:17:35 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 193.202.12.18 | Target: wplogin" , client: 193.202.12.18, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-04-26 05:12:20
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 01:12:16.689896 2026] [security2:error] [pid 7898:tid 7898] [client 193.202.12.18:40611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodpage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodpage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae2esD-_eo1bSXujGDzryAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 04:09:54
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 00:09:51.025046 2026] [security2:error] [pid 14929:tid 14929] [client 193.202.12.18:60625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lucitania.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lucitania.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae2QD_2vfdOsEmXy_y6xwwAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-04-21 00:49:48
(4 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
ambor
2026-04-17 14:56:00
(4 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-13 15:42:00
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 193.202.12.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 11:41:56.712742 2026] [security2:error] [pid 1153119:tid 1153119] [client 193.202.12.18:25399] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||more-grace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "more-grace.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad0OxBRdTJZuAUqMjDDVIQAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-03-21 17:30:02
(5 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-21 09:43:05
(5 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking