🇩🇪
stinpriza
2026-09-07 10:19:21
(5 days ago)
Web App Attack
Web App Attack
🇩🇪
big-cloud.nl
2026-09-07 09:45:07
(5 days ago)
Try to access /xmlrpc.php
Web App Attack
🇩🇪
AbuseBaer
2026-09-05 18:19:08
(6 days ago)
access attempt detected by IDS script (C)
Web App Attack
🇩🇪
LRob
2026-08-30 16:42:04
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /le-groupe/nos-filiales/dg-consultants/wp-login.php | 2026-08-30 16:42 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2023-12-17 11:22:06
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 06:22:01.749750 2023] [security2:error] [pid 4666:tid 47751308121856] [client 2a02:752:0:18::1726:37536] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tameladreyerlcsw.workconfident.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tameladreyerlcsw.workconfident.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX7Z2QlW-EzQbj8xPOcGZwAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2023-12-17 10:43:23
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 05:43:19.892495 2023] [security2:error] [pid 16023] [client 2a02:752:0:18::1726:60876] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coolcustomweddingproducts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coolcustomweddingproducts.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX7Qx6Rh51LVf51b37eB4AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2023-12-17 10:00:35
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 05:00:31.720273 2023] [security2:error] [pid 19266] [client 2a02:752:0:18::1726:47850] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prostar.industries"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX7Gv09TtP_VhYKqMRHLFwAAAAU"], referer: http://kuns.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2023-12-17 08:49:40
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 03:49:36.681340 2023] [security2:error] [pid 17108:tid 47810933876480] [client 2a02:752:0:18::1726:36006] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||princesscastlebunkbed.davidholls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "princesscastlebunkbed.davidholls.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX62ILqbvZFin5sh4R3nlQAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2023-12-17 08:16:23
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 03:16:18.436558 2023] [security2:error] [pid 13896] [client 2a02:752:0:18::1726:36588] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alpinexport.usaangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alpinexport.usaangelinvestors.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX6uUmi_ZaCMg4sLd_YOPwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2023-12-17 07:58:36
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 02:58:29.359416 2023] [security2:error] [pid 27833] [client 2a02:752:0:18::1726:46654] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thebrotherhoodlounge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thebrotherhoodlounge.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX6qJdXGg0VpukT3NJ7_hQAAAAM"], referer: http://thebroho.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2023-12-17 07:05:39
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 02:05:31.767125 2023] [security2:error] [pid 530] [client 2a02:752:0:18::1726:44504] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.method1.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.method1.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZX6du6z4FycjYtM8JN1E-wAAAAw"], referer: http://method1.biz///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Ba-Yu
2023-12-12 02:16:02
(2 years ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2023-11-18 07:47:07
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 18 02:47:01.497839 2023] [security2:error] [pid 5751:tid 47837808731904] [client 2a02:752:0:18::1726:45822] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||managementlaw.property-management-companies-chicago.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "managementlaw.property-management-companies-chicago.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVhr9df_YIjbBCbTA6ngwgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2023-11-17 16:07:49
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 11:07:41.140067 2023] [security2:error] [pid 4255] [client 2a02:752:0:18::1726:40888] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clairekahndesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clairekahndesign.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVePzW19dqyV-Da83s3PQAAAAA4"], referer: http://clairekahn.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2023-11-17 15:45:01
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:752:0:18::1726 (2a02-752-0-18--1726-static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 10:44:57.224767 2023] [security2:error] [pid 31902] [client 2a02:752:0:18::1726:43748] [client 2a02:752:0:18::1726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lzbvi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lzbvi.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZVeKef0j83VRLaS4OXGo9QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack