πΊπΈ
TPI-Abuse
2026-06-17 03:15:15
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 23:15:06.677096 2026] [security2:error] [pid 15616:tid 15616] [client 212.227.160.24:41478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.greensandbeans.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.greensandbeans.us"] [uri "/wp-json/wp/v2/users"] [unique_id "ajIROv6EaKlMvjiQ0qbO_QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 02:52:46
(1 day ago)
[redacted] 212.227.160.24 - - [16/Jun/2026:04:52:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" " ...
show more
[redacted] 212.227.160.24 - - [16/Jun/2026:04:52:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0"
[redacted] 212.227.160.24 - - [16/Jun/2026:04:52:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0"
[redacted] 212.227.160.24 - - [16/Jun/2026:04:52:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0"
[redacted] 212.227.160.24 - - [16/Jun/2026:04:52:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
[redacted] 212.227.160.24 - - [16/Jun/2026:04:52:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0"
[redacted] 212.227.160.24 - - [16/Jun/2026:04:52:42 +0200] "POST /xmlrpc.php HTTP/1
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 20:09:40
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 16:09:32.542949 2026] [security2:error] [pid 3579:tid 3591] [client 212.227.160.24:59578] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leadingedgesupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leadingedgesupply.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai8KfFayIHCpkXHkXfZ6MwAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 21:11:12
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 17:11:05.871511 2026] [security2:error] [pid 16923:tid 16923] [client 212.227.160.24:36952] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jennyfiore.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jennyfiore.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai3HaXVU4rOd4X9Y_5SLmwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-13 16:03:12
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-12 22:50:54
(5 days ago)
[redacted] 212.227.160.24 - - [13/Jun/2026:00:50:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" " ...
show more
[redacted] 212.227.160.24 - - [13/Jun/2026:00:50:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0"
[redacted] 212.227.160.24 - - [13/Jun/2026:00:50:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0"
[redacted] 212.227.160.24 - - [13/Jun/2026:00:50:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0"
[redacted] 212.227.160.24 - - [13/Jun/2026:00:50:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0"
[redacted] 212.227.160.24 - - [13/Jun/2026:00:50:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0"
[redacted] 212.22
...
show less
Hacking
Web App Attack
π«π·
SpaceHost-Server
2026-06-11 22:30:03
(6 days ago)
Brute-Force
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-06-11 17:12:16
(6 days ago)
Blocked by CSF 13 firewall - Rule: DE/Germany/-
Web App Attack
πΊπΈ
bigwavedave
2026-06-11 07:24:26
(6 days ago)
Wordpress Attack
Web App Attack
π«π·
SpaceHost-Server
2026-06-10 22:29:05
(1 week ago)
Brute-Force
Web App Attack
Anonymous
2026-06-10 18:39:06
(1 week ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-06-10 04:17:15
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 00:17:09.831709 2026] [security2:error] [pid 26936:tid 26946] [client 212.227.160.24:55136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.scottspencergfx.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.scottspencergfx.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aijlRZ1lpqIjn3mccovX3wAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 07:19:53
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 03:19:48.290925 2026] [security2:error] [pid 30280:tid 30310] [client 212.227.160.24:42578] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.plumeraproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.plumeraproductions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiUblG3ptCvwVL1UIKrjVgAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-06-06 13:14:19
(1 week ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-05 18:48:00
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.227.160.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 14:47:56.343847 2026] [security2:error] [pid 8321:tid 8321] [client 212.227.160.24:39514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nextstepplus.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nextstepplus.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aiMZ3NFu3Vz5RsrtWnYwNgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack