๐บ๐ธ
TPI-Abuse
2026-06-08 17:38:15
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:38:08.395031 2026] [security2:error] [pid 10444:tid 10444] [client 2a00:1098:88:34::1:33990] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||altoshp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "altoshp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aib-ACK_i8tB-VcPjc8qvwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 05:43:48
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 01:43:42.841913 2026] [security2:error] [pid 13141:tid 13141] [client 2a00:1098:88:34::1:39300] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.georgegourmet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.georgegourmet.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiUFDvFd-NV1tPYM-hnQjwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-07 02:50:25
(4 days ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-07 02:32:12
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 14:00:13
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 09:59:57.391619 2026] [security2:error] [pid 21401:tid 21401] [client 2a00:1098:88:34::1:48762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vzan.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vzan.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aiQn3Sohf7Esk9Fbzyy6hAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 15:38:34
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 11:38:26.180874 2026] [security2:error] [pid 6267:tid 6267] [client 2a00:1098:88:34::1:56884] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iplayriichi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iplayriichi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agH38vFLRRlzRMQWdF7uuAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 03:59:19
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 23:59:12.302210 2026] [security2:error] [pid 3660:tid 3660] [client 2a00:1098:88:34::1:48772] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||solucionesmercadeodigital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "solucionesmercadeodigital.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agFUEPVDGROYrxiH8snkWgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 07:16:19
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a00:1098:88:34::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 03:16:14.848340 2026] [security2:error] [pid 2415:tid 2415] [client 2a00:1098:88:34::1:45804] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.prcomputersolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.prcomputersolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agAwvrh1lZC8mDiww-4JKQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kernel-error.de
2025-08-05 13:58:48
(10 months ago)
2a00:1098:88:34::1 - - [05/Aug/2025:01:13:05 +0200] "POST /xmlrpc.php HTTP/1.1" 403 227 "-" "Mozilla ...
show more
2a00:1098:88:34::1 - - [05/Aug/2025:01:13:05 +0200] "POST /xmlrpc.php HTTP/1.1" 403 227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0"
2a00:1098:88:34::1 - - [05/Aug/2025:01:54:48 +0200] "POST /xmlrpc.php HTTP/1.1" 403 227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0"
2a00:1098:88:34::1 - - [05/Aug/2025:15:58:47 +0200] "POST /xmlrpc.php HTTP/1.1" 403 227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2025-08-04 12:30:29
(10 months ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
LRob.fr
2025-08-04 05:00:16
(10 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ฎ
FlexPete
2025-08-03 23:59:59
(10 months ago)
Web related brute force 20250803
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
Max la Menace
2025-08-03 21:41:57
(10 months ago)
Wordpress Attack (P)
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-08-03 12:59:04
(10 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-05-13 04:49:39
(1 year ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack