🇫🇮
6kilowatti
2026-07-30 14:50:59
(4 weeks ago)
2a0f:13c0::2 - - [30/Jul/2026:17:50:59 +0300] "POST /xmlrpc.php HTTP/1.1" 403 75 "-" "Mozilla/5.0 (W ...
show more
2a0f:13c0::2 - - [30/Jul/2026:17:50:59 +0300] "POST /xmlrpc.php HTTP/1.1" 403 75 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
2a0f:13c0::2 - [30/Jul/2026:17:50:59 +0300] "POST /xmlrpc.php HTTP/1.1" 403 8192 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
Web App Attack
🇩🇪
ger-stg-sifi1
2026-07-28 08:04:45
(1 month ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
LRob
2026-07-27 02:56:58
(1 month ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.4 ...
show more
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.43 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 OPR/124.0.0.0
show less
Brute-Force
Web App Attack
🇩🇪
ger-stg-sifi1
2026-07-26 23:35:31
(1 month ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
LRob
2026-07-26 11:32:50
(1 month ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.3 ...
show more
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-13 12:22:35
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 08:22:30.558453 2026] [security2:error] [pid 3747:tid 3747] [client 2a0f:13c0::2:57527] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.alsetsystems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.alsetsystems.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agRtBsKEfe7_ZFJnQQCobwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-13 02:17:35
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 22:17:29.225685 2026] [security2:error] [pid 27235:tid 27235] [client 2a0f:13c0::2:9748] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aseguratuauto.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aseguratuauto.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agPfOVYcwIQ6x16yvx0SIwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-13 01:21:39
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 21:21:31.664947 2026] [security2:error] [pid 25516:tid 25526] [client 2a0f:13c0::2:32875] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daraluz.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daraluz.net"] [uri "/wp-json/wp/v2/users"] [unique_id "agPSG6X5tk-rj48GQwRu5gAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-05-12 16:20:10
(3 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
LRob
2026-05-11 23:00:13
(3 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-10 18:19:27
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 14:19:20.114610 2026] [security2:error] [pid 11291:tid 11291] [client 2a0f:13c0::2:16147] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kairoslogammakmur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kairoslogammakmur.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agDMKNJfGn8UwgB6Be6htAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 11:22:24
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 07:22:18.204687 2026] [security2:error] [pid 16616:tid 16616] [client 2a0f:13c0::2:2569] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kawkacevents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kawkacevents.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agBqarnT9SOfAd-0fhGfpAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-05-10 09:54:15
(3 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 04:55:17
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 00:55:11.531868 2026] [security2:error] [pid 8671:tid 8684] [client 2a0f:13c0::2:45113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||whitecrosslibrary.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "whitecrosslibrary.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agAPr6rPKexSiApvVYYwEQAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 01:23:26
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0f:13c0::2 (qodx.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 21:23:21.065284 2026] [security2:error] [pid 13254:tid 13254] [client 2a0f:13c0::2:14409] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.eileensharaga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.eileensharaga.com"] [uri "/wp-json/wp/v2/users"] [unique_id "af_eCUOoPND3HiZi3vnOugAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack