🇸🇬
Cloudkul Cloudkul
2026-05-30 04:50:44
(3 months ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-29 16:16:01
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 12:15:54.014673 2026] [security2:error] [pid 462:tid 462] [client 2001:41d0:8:cc78:::50660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rochesterhistorical.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rochesterhistorical.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ahm7ut6GyzbB57S7UHUKLgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
bigwavedave
2026-05-29 15:19:32
(3 months ago)
Wordpress Attack
Web App Attack
🇩🇪
lenz
2026-05-29 06:43:58
(3 months ago)
May 29 08:43:58 hosting wordpress(grupa-ddd.pl)[1204]: XML-RPC authentication failure for admin from ...
show more
May 29 08:43:58 hosting wordpress(grupa-ddd.pl)[1204]: XML-RPC authentication failure for admin from 2001:41d0:8:cc78::
May 29 08:43:58 hosting wordpress(grupa-ddd.pl)[2270]: XML-RPC authentication failure for admin from 2001:41d0:8:cc78::
May 29 08:43:58 hosting wordpress(grupa-ddd.pl)[1203]: XML-RPC authentication failure for admin from 2001:41d0:8:cc78::
May 29 08:43:58 hosting wordpress(grupa-ddd.pl)[6431]: Authentication failure for admin from 2001:41d0:8:cc78::
May 29 08:43:58 hosting wordpress(grupa-ddd.pl)[1200]: Authentication failure for admin from 2001:41d0:8:cc78::
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-27 18:58:42
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 14:58:39.171316 2026] [security2:error] [pid 22002:tid 22002] [client 2001:41d0:8:cc78:::51412] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drdot.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drdot.xyz"] [uri "/wp-json/wp/v2/users"] [unique_id "ahc-3-wZbKwaC6cDYYoKsgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-27 15:40:03
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 11:39:57.940362 2026] [security2:error] [pid 25622:tid 25622] [client 2001:41d0:8:cc78:::55372] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.feministvoice.blog|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.feministvoice.blog"] [uri "/wp-json/wp/v2/users"] [unique_id "ahcQTYnO0ae5aEk3_cCfPQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-25 15:55:14
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 11:55:10.036300 2026] [security2:error] [pid 2239:tid 2255] [client 2001:41d0:8:cc78:::32856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ccgparquitectos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ccgparquitectos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahRw3hFSiWX9pAtHqqruAQAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-24 19:15:23
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 15:15:19.442387 2026] [security2:error] [pid 20204:tid 20204] [client 2001:41d0:8:cc78:::57380] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dancingbearprinting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dancingbearprinting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahNOR-ipEzcs7YociyAT7AAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Brict IT
2026-05-22 19:34:26
(3 months ago)
Bad Web Bot
Web App Attack
🇩🇪
reznekcs
2026-05-22 02:10:09
(3 months ago)
F2B wordpress ban. Logs: 2001:41d0:8:cc78:: - - [22/May/2026:04:10:07 +0200] "POST /xmlrpc.php HTTP/ ...
show more
F2B wordpress ban. Logs: 2001:41d0:8:cc78:: - - [22/May/2026:04:10:07 +0200] "POST /xmlrpc.php HTTP/2.0" 200 316 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:50.0) Gecko/20100101 Firefox/50.0"
2001:41d0:8:cc78:: - - [22/May/2026:04:10:07 +0200] "POST /xmlrpc.php HTTP/2.0" 200 316 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
show less
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-05-22 00:33:15
(3 months ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-05-21 21:07:15
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 17:07:08.668505 2026] [security2:error] [pid 10751:tid 10751] [client 2001:41d0:8:cc78:::45968] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.reelvisionboard.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.reelvisionboard.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag9z_ImMJVS3_EyJGEAV3wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-05-20 17:00:08
(3 months ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-19 21:06:40
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 17:06:36.714663 2026] [security2:error] [pid 5947:tid 5947] [client 2001:41d0:8:cc78:::37412] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jacquelineperriam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jacquelineperriam.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agzQ3A5qi7SA1ZUO22XmnwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-19 15:27:49
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:41d0:8:cc78:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 11:27:43.747448 2026] [security2:error] [pid 25331:tid 25331] [client 2001:41d0:8:cc78:::47248] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cienmalos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cienmalos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agyBb6XFihdta2uegr1AjQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack