๐ฉ๐ช
neckaralb-admin.de
2026-08-29 06:29:15
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ง๐ช
taivas.nl
2026-08-29 06:02:15
(2 days ago)
Wordpress_xmlrpc_attack
Bad Web Bot
๐ฎ๐น
VHosting
2026-08-28 23:30:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-28 22:54:17
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-28 21:09:41
(2 days ago)
2026-08-28T23:09:40.546126+02:00 aion wordpress[4056631]: Blocked user enumeration attempt from 195. ...
show more
2026-08-28T23:09:40.546126+02:00 aion wordpress[4056631]: Blocked user enumeration attempt from 195.88.211.214
...
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 14:59:43
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:59:37.005877 2026] [security2:error] [pid 30733:tid 30733] [client 195.88.211.214:60076] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||athletefirst.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "athletefirst.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apGiWVe66sVb6Rb9j2OUdwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:33:11
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:33:04.682381 2026] [security2:error] [pid 19664:tid 19697] [client 195.88.211.214:46744] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||conservativelabor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "conservativelabor.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apGcIHOzscTQeWZ4X8C6HgAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 10:39:34
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:39:28.725029 2026] [security2:error] [pid 28004:tid 28004] [client 195.88.211.214:48274] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||armorcorp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "armorcorp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apFlYPVIUEUK125hqCv8dQAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-28 10:13:32
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 10:09:08
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:09:00.343075 2026] [security2:error] [pid 12507:tid 12507] [client 195.88.211.214:59830] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rotentendales.aticom.es|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rotentendales.aticom.es"] [uri "/wp-json/wp/v2/users"] [unique_id "apFePLlREBQpeaU-yoiK8AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 11:50:50
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:50:45.270757 2026] [security2:error] [pid 16665:tid 16665] [client 195.88.211.214:53520] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||xcarsubscription.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "xcarsubscription.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao7TFaFQPRgoXmViSrtU_gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 11:33:57
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 08:47:33
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:47:28.154865 2026] [security2:error] [pid 31806:tid 31806] [client 195.88.211.214:57926] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thorndikestudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6oIFIQC1Dl1sUGJIV81wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-26 07:31:31
(4 days ago)
[WedAug2609:31:23.4960792026][security2:error][pid3594313:tid3594381][client195.88.211.214:0]ModSecu ...
show more
[WedAug2609:31:23.4960792026][security2:error][pid3594313:tid3594381][client195.88.211.214:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"614\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"avvnicolaurbani.ch\"][uri\"/xmlrpc.php\"][unique_id\"ao6WS1u3x_8AFlL0XG38kAAAAYw\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 06:11:20
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 195.88.211.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 02:11:14.896140 2026] [security2:error] [pid 14278:tid 14278] [client 195.88.211.214:44840] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eta-mct.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eta-mct.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6Dgn6MYVUdqLYIm1K_UAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack