🇺🇸
factor1
2026-06-25 00:35:13
(2 months ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
🇩🇪
LRob
2026-06-24 23:30:11
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇩🇪
reznekcs
2026-06-23 20:02:15
(2 months ago)
F2B wordpress ban. Logs: 2001:41d0:8:cc78:: - - [23/Jun/2026:22:02:13 +0200] "POST /xmlrpc.php HTTP/ ...
show more
F2B wordpress ban. Logs: 2001:41d0:8:cc78:: - - [23/Jun/2026:22:02:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0"
2001:41d0:8:cc78:: - - [23/Jun/2026:22:02:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0"
show less
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-06-22 14:14:49
(2 months ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-06-22 13:48:48
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 09:48:40.711286 2026] [security2:error] [pid 26217:tid 26217] [client 2001:41d0:8:cc78:::56330] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||richmondrents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "richmondrents.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajk9ONnrBQt9eLIuN963IAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-22 11:30:46
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 07:30:37.960754 2026] [security2:error] [pid 24974:tid 24974] [client 2001:41d0:8:cc78:::55932] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bickleton.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkc3ZtJ7IryYqjTuYAx7QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-22 07:48:25
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 03:48:20.919054 2026] [security2:error] [pid 2003:tid 2003] [client 2001:41d0:8:cc78:::42694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.calvaryadminservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.calvaryadminservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajjoxCBKrzThRv1ZGoNSLwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-21 05:02:53
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 01:02:40.828096 2026] [security2:error] [pid 18728:tid 18728] [client 2001:41d0:8:cc78:::45810] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.stop902.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.stop902.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdwcJulbb1d2gOWs037HAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-21 03:46:00
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 23:45:53.681581 2026] [security2:error] [pid 19791:tid 19791] [client 2001:41d0:8:cc78:::42704] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vzan.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vzan.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdecR6t9-Ga1Jp8VoQ_AQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-06-20 13:44:03
(2 months ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-06-20 07:02:43
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 03:02:37.450044 2026] [security2:error] [pid 19465:tid 19474] [client 2001:41d0:8:cc78:::39224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.campingcosmetics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.campingcosmetics.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajY7DVDxm6Cfk8NWhtQJNQAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-20 06:05:33
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 02:05:27.874054 2026] [security2:error] [pid 16661:tid 16661] [client 2001:41d0:8:cc78:::43722] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajYtp_jJQ_mPkuipZ3E06wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-18 23:21:28
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 19:21:19.776407 2026] [security2:error] [pid 14473:tid 14473] [client 2001:41d0:8:cc78:::35122] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||learnserve.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "learnserve.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajR9b4rM_6x5TJPTV57SrQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-18 02:53:23
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 22:53:16.896976 2026] [security2:error] [pid 23706:tid 23706] [client 2001:41d0:8:cc78:::35798] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.margroberts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.margroberts.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajNdnI3tvrhJpNuKohQBngAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-17 13:30:26
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 09:30:22.135197 2026] [security2:error] [pid 8744:tid 8744] [client 2001:41d0:8:cc78:::39930] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ibermar.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ibermar.info"] [uri "/wp-json/wp/v2/users"] [unique_id "ajKhbgR8Ep_pKPu8eLlsWAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack