๐ฉ๐ช
reznekcs
2026-06-18 06:57:27
(3 months ago)
F2B wordpress ban. Logs: 2a01:4f8:191:80ea::2 - - [18/Jun/2026:08:57:26 +0200] "POST /xmlrpc.php HTT ...
show more
F2B wordpress ban. Logs: 2a01:4f8:191:80ea::2 - - [18/Jun/2026:08:57:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0"
2a01:4f8:191:80ea::2 - - [18/Jun/2026:08:57:27 +0200] "POST /wp-login.php HTTP/1.1" 200 3782 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0"
show less
Brute-Force
Web App Attack
Anonymous
2026-06-18 03:02:10
(3 months ago)
Attac
Brute-Force
๐ณ๐ฑ
middelkoopcc
2026-06-18 02:25:06
(3 months ago)
2026-06-18 04:23:00 WordPress login error from 2a01:4f8:191:80ea::2: incorrect_password && 2026-06-1 ...
show more
2026-06-18 04:23:00 WordPress login error from 2a01:4f8:191:80ea::2: incorrect_password && 2026-06-18 04:23:00 WordPress login error from 2a01:4f8:191:80ea::2: incorrect_password && 2026-06-18 04:23:00 WordPress login error from 2a01:4f8:191:80ea::2: incorrect_password && 134 more within 20 minutes
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-18 02:14:11
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 22:14:06.954806 2026] [security2:error] [pid 13481:tid 13481] [client 2a01:4f8:191:80ea::2:33682] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jazziiafoundation.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajNUbqwl7k2wvm1q6ogwxgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 22:28:58
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 18:28:51.782463 2026] [security2:error] [pid 9163:tid 9188] [client 2a01:4f8:191:80ea::2:55044] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.abusaimeh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.abusaimeh.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajMfoyb9X34zsLcMTBtUwgAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-17 15:03:13
(3 months ago)
(wp_login_try) srv104 WP Login Attempt 2a01:4f8:191:80ea::2 (DE/Germany/-): 10 in the last 3600 secs ...
show more
(wp_login_try) srv104 WP Login Attempt 2a01:4f8:191:80ea::2 (DE/Germany/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 09:09:29
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 05:09:23.343753 2026] [security2:error] [pid 20069:tid 20069] [client 2a01:4f8:191:80ea::2:59072] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.earthtwoworkshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.earthtwoworkshop.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "ajJkQ9h5Qe_aw5uXJwtu1QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 08:11:12
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 04:11:08.751886 2026] [security2:error] [pid 28470:tid 28470] [client 2a01:4f8:191:80ea::2:33966] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.technesa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.technesa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajJWnLqonPwolylKzX28WgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 05:18:53
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 01:18:45.384838 2026] [security2:error] [pid 16999:tid 16999] [client 2a01:4f8:191:80ea::2:57334] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.paleopathologist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.paleopathologist.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajIuNZqXgM1idKEDE0-mBAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 06:59:34
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 02:59:30.469123 2026] [security2:error] [pid 2397:tid 2397] [client 2a01:4f8:191:80ea::2:57682] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.disio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.disio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajD0Um9gZ1MWw1_hZFfzAwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 06:22:13
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 02:22:08.640197 2026] [security2:error] [pid 30622:tid 30622] [client 2a01:4f8:191:80ea::2:34458] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dragonflytunes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dragonflytunes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajDrkPnzHSDXMKbvTQs7hwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 22:23:46
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 18:23:38.985388 2026] [security2:error] [pid 22847:tid 22847] [client 2a01:4f8:191:80ea::2:44902] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rocksolidhomebuilders.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rocksolidhomebuilders.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajB7anLyKcRemsczRkPvVAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 10:26:51
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 06:26:47.032009 2026] [security2:error] [pid 11330:tid 11330] [client 2a01:4f8:191:80ea::2:45328] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bosdkbook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bosdkbook.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_TZ2HQK5Jbz7s18yfrkgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 09:52:23
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f8:191:80ea::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:52:18.084691 2026] [security2:error] [pid 23306:tid 23380] [client 2a01:4f8:191:80ea::2:57510] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.metropaint.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.metropaint.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_LUtTEo4FTfldUanujHQAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 06:24:10
(3 months ago)
Attac
Brute-Force