Anonymous
2026-09-20 20:09:14
(2 days ago)
2026-09-20T22:06:49.889221+02:00 wordpress(www.ferienfreude.com)[3245062]: Blocked user enumeration ...
show more
2026-09-20T22:06:49.889221+02:00 wordpress(www.ferienfreude.com)[3245062]: Blocked user enumeration attempt from 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 18:11:16
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.i ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.ixlhosting.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:11:10.676489 2026] [security2:error] [pid 5822:tid 5822] [client 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b:57176] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||twogocamping.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "twogocamping.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arAhvuOE5xoORAOBUJn6QQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 14:50:33
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
todix
2026-09-20 05:23:18
(3 days ago)
WebAttack or semilar from 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 01:43:50
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.i ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.ixlhosting.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:43:43.596320 2026] [security2:error] [pid 12898:tid 12898] [client 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b:46226] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pixelspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pixelspective.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq86T3XF6yxBEdxrhtxypAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 21:59:50
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.i ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.ixlhosting.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 17:59:44.547841 2026] [security2:error] [pid 11125:tid 11125] [client 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b:60608] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pinetreedistrict.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pinetreedistrict.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8F0NlY72mTgAvhPC_xmQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-19 20:07:48
(3 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (-): 1 in t ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b - - [19/Sep/2026:22:07:46 +0200] "GET /wp-json/wp/v2/users HTTP/2.0" 200 4818 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0" "2a01:7c8:bb0e:9a:5054:ff:fe95:c59b" host=www.consorzioaet.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 18:43:58
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.i ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.ixlhosting.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:43:45.970679 2026] [security2:error] [pid 4274:tid 4274] [client 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b:41970] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pcga.golf|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pcga.golf"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7X4Z_W4pE1obg_RZb-6wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-09-19 10:30:49
(4 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-18 22:19:36
(4 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:19:33
(5 days ago)
Brute-Force
Web App Attack
๐ฉ๐ช
stinpriza
2026-09-17 21:35:33
(5 days ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-17 17:34:13
(5 days ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 16:43:44
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.i ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.ixlhosting.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:43:39.821410 2026] [security2:error] [pid 32525:tid 32541] [client 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b:33338] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||colegiopiramide.edu.gt|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "colegiopiramide.edu.gt"] [uri "/wp-json/wp/v2/users"] [unique_id "aqwYuzMV5AOJfd5wIAE0yQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 11:38:54
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.i ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b (db11159-1.ixlhosting.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:38:39.953579 2026] [security2:error] [pid 20953:tid 20953] [client 2a01:7c8:bb0e:9a:5054:ff:fe95:c59b:52778] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tarekshohaieb.online|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tarekshohaieb.online"] [uri "/wp-json/wp/v2/users"] [unique_id "aqvRP6sdU-RJ6NPOTHyw5gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack