๐ณ๐ฑ
Mangelot Hosting
2025-12-19 21:37:31
(8 months ago)
(wp_login_try) srv102 WP Login Attempt 2604:a880:400:d1::899:4001 (Unknown): 10 in the last 3600 sec ...
show more
(wp_login_try) srv102 WP Login Attempt 2604:a880:400:d1::899:4001 (Unknown): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
Rey
2025-12-15 09:08:01
(8 months ago)
WordPress xmlrpc.php attack [zqvg669f]
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-12-04 02:29:11
(8 months ago)
WordPress bruteforce
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2025-11-21 07:45:18
(9 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
Rey
2025-11-21 04:14:02
(9 months ago)
WordPress xmlrpc.php attack [7z62im79]
Web App Attack
๐บ๐ธ
xmission.com
2025-11-21 04:08:55
(9 months ago)
2604:a880:400:d1::899:4001 - - [20/Nov/2025:21:08:55 -0700] "POST /xmlrpc.php HTTP/1.1" 200 413 "-" ...
show more
2604:a880:400:d1::899:4001 - - [20/Nov/2025:21:08:55 -0700] "POST /xmlrpc.php HTTP/1.1" 200 413 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:85.0) Gecko/20100101 Firefox/91.0"
...
show less
Web App Attack
๐ฉ๐ช
stinpriza
2025-11-19 05:15:10
(9 months ago)
Web App Attack
Web App Attack
๐ฉ๐ช
LRob
2025-11-17 17:36:21
(9 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-14 15:17:39
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 10:17:35.665477 2025] [security2:error] [pid 8033:tid 8033] [client 2604:a880:400:d1::899:4001:43976] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||monogay.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "monogay.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRdID7eVjCbXBDpzpx7RyAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 07:36:13
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 02:36:09.785892 2025] [security2:error] [pid 4172637:tid 4172637] [client 2604:a880:400:d1::899:4001:56214] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rachelfia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rachelfia.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRWKaRlCtEtBSgAGjJEXgQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 05:56:38
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 00:56:34.353850 2025] [security2:error] [pid 24987:tid 24987] [client 2604:a880:400:d1::899:4001:35290] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tcomputerguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tcomputerguy.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRVzEtuRFoXw0DgP-Er6kgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 04:22:17
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 23:22:10.409057 2025] [security2:error] [pid 24201:tid 24201] [client 2604:a880:400:d1::899:4001:60948] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hawarcenter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hawarcenter.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRVc8jSJgnG9OlExDOQ2WQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 03:50:27
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 2604:a880:400:d1::899:4001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 22:50:21.780695 2025] [security2:error] [pid 10791:tid 10791] [client 2604:a880:400:d1::899:4001:60666] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||market1st.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "market1st.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRVVfdYCPdERdYTegQlPKgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
stinpriza
2025-11-11 09:56:02
(9 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
xmission.com
2025-11-11 08:07:33
(9 months ago)
2604:a880:400:d1::899:4001 - - [11/Nov/2025:01:07:32 -0700] "POST /xmlrpc.php HTTP/1.1" 302 138 "-" ...
show more
2604:a880:400:d1::899:4001 - - [11/Nov/2025:01:07:32 -0700] "POST /xmlrpc.php HTTP/1.1" 302 138 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:85.0) Gecko/20100101 Firefox/91.0"
...
show less
Web App Attack