๐บ๐ธ
TPI-Abuse
2025-07-31 06:04:12
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:10b:262::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:10b:262::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 31 02:04:05.820564 2025] [security2:error] [pid 9074:tid 9074] [client 2a01:4f8:10b:262::2:42142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||edmundtadros.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "edmundtadros.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIsHVZK53cu7_ZOfKOSzFgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-30 20:34:21
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:10b:262::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:10b:262::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 30 16:34:15.280317 2025] [security2:error] [pid 11934:tid 11958] [client 2a01:4f8:10b:262::2:37200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chaoticperception.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chaoticperception.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIqBx0a-vcg7EPKFowgefQAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-07-22 23:40:02
(11 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2025-07-22 21:30:26
(11 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
corthorn
2023-12-06 17:01:29
(2 years ago)
2a01:4f8:10b:262::2 - - [06/Dec/2023:18:01:29 +0100] "POST /xmlrpc.php HTTP/1.1" 403 5557 "-" "Mozil ...
show more
2a01:4f8:10b:262::2 - - [06/Dec/2023:18:01:29 +0100] "POST /xmlrpc.php HTTP/1.1" 403 5557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.186 Safari/537.36"
...
show less
Brute-Force
๐ฌ๐ง
Swiptly
2023-11-25 06:49:20
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
applemooz
2023-11-21 10:25:16
(2 years ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-17 16:02:33
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:10b:262::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:10b:262::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 11:02:26.561317 2023] [security2:error] [pid 12604:tid 47153891059456] [client 2a01:4f8:10b:262::2:35994] [client 2a01:4f8:10b:262::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fibertechsystems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fibertechsystems.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZVeOkqHgcAgXeiBIPcCs4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-17 10:01:57
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:10b:262::2 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:10b:262::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 05:01:54.655703 2023] [security2:error] [pid 17092] [client 2a01:4f8:10b:262::2:34800] [client 2a01:4f8:10b:262::2] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gaeltv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gaeltv.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZVc6ErGFBupQtsgoRqOPWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
corthorn
2023-11-04 14:19:17
(2 years ago)
2a01:4f8:10b:262::2 - - [04/Nov/2023:15:19:16 +0100] "POST /xmlrpc.php HTTP/1.1" 403 5575 "-" "Mozil ...
show more
2a01:4f8:10b:262::2 - - [04/Nov/2023:15:19:16 +0100] "POST /xmlrpc.php HTTP/1.1" 403 5575 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
...
show less
Brute-Force
๐ซ๐ท
Max la Menace
2023-10-20 08:45:40
(2 years ago)
Wordpress attack (F)
Blog Spam
Web App Attack
๐ฉ๐ช
iNetWorker
2023-10-20 06:49:45
(2 years ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ช
ps-center
2023-10-20 01:44:16
(2 years ago)
C1: Web Attack GET /manga/wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2023-10-19 17:20:38
(2 years ago)
(wordpress) Failed wordpress login from 2a01:4f8:10b:262::2 (DE/Germany/Bavaria/Landshut/-/[redacted ...
show more
(wordpress) Failed wordpress login from 2a01:4f8:10b:262::2 (DE/Germany/Bavaria/Landshut/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐ฉ๐ช
ps-center
2023-10-15 19:48:54
(2 years ago)
ABV: Web Attack GET /ruetten-loening/wp-login.php
Web Spam
Hacking
Bad Web Bot
Web App Attack