๐ฉ๐ช
LRob.fr
2026-06-26 19:30:03
(19 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-25 17:15:08
(1 day ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐บ๐ธ
factor1
2026-06-25 13:16:20
(2 days ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-25 08:04:05
(2 days ago)
Wordfence waf block on 1105merrystreet
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-24 18:30:02
(2 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 10:19:12
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh. ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 06:19:06.306934 2026] [security2:error] [pid 5068:tid 5068] [client 2001:41d0:601:1100::8863:41490] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bamedica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajpdmng5DP46hLX_JOy7mgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-23 05:12:35
(4 days ago)
(wordpress) Failed wordpress login from 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh.net): (CF_EN ...
show more
(wordpress) Failed wordpress login from 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh.net): (CF_ENABLE)
show less
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-06-22 22:29:45
(4 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 12:32:02
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh. ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 08:31:56.216317 2026] [security2:error] [pid 32176:tid 32176] [client 2001:41d0:601:1100::8863:40450] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.riser-astrology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.riser-astrology.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkrPO03jOP7-YvZWvpQagAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 11:58:44
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh. ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 07:58:38.225367 2026] [security2:error] [pid 12938:tid 12938] [client 2001:41d0:601:1100::8863:33136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "major33.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkjbvJu-fHbJyUsiVRloAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-22 06:00:04
(5 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-21 20:24:23
(5 days ago)
(wp_login_try) srv102 WP Login Attempt 2001:41d0:601:1100::8863 (PL/Poland/-): 10 in the last 3600 s ...
show more
(wp_login_try) srv102 WP Login Attempt 2001:41d0:601:1100::8863 (PL/Poland/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-06-20 14:06:31
(1 week ago)
2001:41d0:601:1100::8863 - - > www.allacasadilucia.it [20/Jun/2026:16:06:31 +0200] "POST /xmlrpc.php ...
show more
2001:41d0:601:1100::8863 - - > www.allacasadilucia.it [20/Jun/2026:16:06:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "-"
2001:41d0:601:1100::8863 - - > www.allacasadilucia.it [20/Jun/2026:16:06:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0" "-"
2001:41d0:601:1100::8863 - - > www.allacasadilucia.it [20/Jun/2026:16:06:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0" "-"
2001:41d0:601:1100::8863 - - > www.allacasadilucia.it [20/Jun/2026:16:06:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0" "-"
2001:41d0:601:1100::8863 - - > www.allacasadilucia.it [20/Jun/2026:16:06:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 18:05:47
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh. ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 14:05:41.147852 2026] [security2:error] [pid 21372:tid 21372] [client 2001:41d0:601:1100::8863:60428] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.thingstodonude.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.thingstodonude.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWE9b9Vrp9CmVQmoZh1XwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 16:06:52
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh. ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:601:1100::8863 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 12:06:47.161604 2026] [security2:error] [pid 19300:tid 19300] [client 2001:41d0:601:1100::8863:37818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doctorbalog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doctorbalog.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajVpF_RXJ3Zakz_Hd6iuSgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack