Anonymous
2026-09-25 22:42:48
(1 week ago)
Port Scanner
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-14 18:54:34
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 14:54:28.514473 2026] [security2:error] [pid 21341:tid 21341] [client 217.64.126.118:55364] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marlinlee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marlinlee.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alaF5IKLannR2DpiEKwlugAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-14 18:51:18
(2 months ago)
[TueJul1420:51:14.3335632026][security2:error][pid2540046:tid2540054][client217.64.126.118:0]ModSecu ...
show more
[TueJul1420:51:14.3335632026][security2:error][pid2540046:tid2540054][client217.64.126.118:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"esengineering.ch\"][uri\"/xmlrpc.php\"][unique_id\"alaFInpVN0UsWAhO6FxDFwAAAEU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 10:33:07
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 06:33:02.731024 2026] [security2:error] [pid 11035:tid 11035] [client 217.64.126.118:52427] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 217.64.126.118 (+1 hits since last alert)|tek-front.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tek-front.com"] [uri "/xmlrpc.php"] [unique_id "aj5VXofzxelKNVXESsU9GAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-05-03 14:00:05
(5 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-03-27 17:00:06
(6 months ago)
Wordfence waf block on pameganslaw
Web App Attack
๐ฎ๐น
VHosting
2026-03-14 06:15:11
(6 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-03-01 01:08:49
(7 months ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (5001900-122)
Web App Attack
๐ฉ๐ช
ps-center
2026-02-24 21:25:50
(7 months ago)
C1: Web Attack GET /wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-19 16:55:35
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 11:55:29.363706 2026] [security2:error] [pid 28815:tid 28815] [client 217.64.126.118:49278] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bruskiewitz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bruskiewitz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aW5iATxvfp9vFAhyldq9HQAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-01-09 19:10:50
(8 months ago)
217.64.126.118 - - [09/Jan/2026:20:10:50 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
217.64.126.118 - - [09/Jan/2026:20:10:50 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
Brute-force password attempt
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-09 08:00:56
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 03:00:49.710952 2026] [security2:error] [pid 7807:tid 7807] [client 217.64.126.118:39302] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fitzmail.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fitzmail.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWC1sQu7y-VKG2fhZvq6CgAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-09 01:51:56
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 217.64.126.118 (goodwood.librios.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 08 20:51:50.175343 2026] [security2:error] [pid 29021:tid 29021] [client 217.64.126.118:42442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chyps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chyps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWBfNkGjXuUvbMaLrox47wAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-12-23 20:21:36
(9 months ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2025-09-19 21:12:06
(1 year ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking