๐บ๐ธ
nationaleventpros.com
2026-01-21 03:41:49
(8 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
myagent.site
2026-01-19 01:44:23
(8 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-24 19:50:10
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 202.92.4.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 202.92.4.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 24 14:50:02.760570 2025] [security2:error] [pid 17983:tid 17983] [client 202.92.4.98:53690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||miroconsulting.es|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "miroconsulting.es"] [uri "/wp-json/wp/v2/users"] [unique_id "aUxD6gQTefegQwiqw0fCYQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2025-12-23 21:03:28
(9 months ago)
Try to access /xmlrpc.php
Web App Attack
๐ฎ๐น
mgarofano80
2025-12-23 12:27:17
(9 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-19 06:55:05
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 202.92.4.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 202.92.4.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 01:55:00.396208 2025] [security2:error] [pid 2236:tid 2239] [client 202.92.4.98:44610] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greaternorthmiamihistory.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greaternorthmiamihistory.org"] [uri "/Wp-JsOn/Wp/V2/UsErS"] [unique_id "aUT2xHVEPKTIFvN6tTYyqgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-16 13:21:18
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
myagent.site
2025-12-14 00:57:27
(9 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฉ๐ช
LRob
2025-12-13 19:34:09
(9 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-12 13:42:22
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 202.92.4.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 202.92.4.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 08:42:15.664308 2025] [security2:error] [pid 16694:tid 16694] [client 202.92.4.98:53766] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aam-artists.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aam-artists.com"] [uri "/wp-json/wp/v2/users.json"] [unique_id "aTwbt2LD40ANe434xlOngQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-12-11 20:10:24
(9 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฉ๐ช
LRob
2025-12-11 07:31:38
(9 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 06:51:59
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 202.92.4.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 202.92.4.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 01:51:54.255346 2025] [security2:error] [pid 19676:tid 19676] [client 202.92.4.98:36646] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||localpetsitters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "localpetsitters.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTpqCq7288KKla_6y4_1JAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2025-12-10 23:43:03
(9 months ago)
Brute-Force
Web App Attack
๐ฌ๐ง
Swiptly
2025-04-21 17:09:01
(1 year ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack