๐ณ๐ฑ
wlt-blocker
2026-06-16 21:37:54
(3 hours ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 08:11:32
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 04:11:24.800498 2026] [security2:error] [pid 17794:tid 17794] [client 31.141.222.222:56848] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||slimlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "slimlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajEFLBizM2XkWZw5jrUVaAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-16 07:15:11
(18 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-15 13:16:33
(1 day ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 07:28:23
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:28:17.171045 2026] [security2:error] [pid 17078:tid 17078] [client 31.141.222.222:62960] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||loneoakhoney.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "loneoakhoney.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-pkWZUBLI3SCNOmRl3_QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:36:05
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:35:59.960446 2026] [security2:error] [pid 11443:tid 11443] [client 31.141.222.222:55861] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jazziiafoundation.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-PPwc7_ND41_2DJ3jkSgAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-15 05:10:02
(1 day ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:54:55
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:54:51.746538 2026] [security2:error] [pid 21431:tid 21458] [client 31.141.222.222:64905] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eliteproductions.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eliteproductions.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "ai9ba-OFffrT3dgPM6r47QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 05:47:37
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:47:30.473885 2026] [security2:error] [pid 24800:tid 24800] [client 31.141.222.222:50301] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ismaelcavazos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ismaelcavazos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai5Acu1U7foow0eoVvVJVAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-06-13 17:08:15
(3 days ago)
-:443 31.141.222.222 - - [13/Jun/2026:19:08:14 +0200] - "POST /xmlrpc.php HTTP/1.1" 404 6439 "-" "Mo ...
show more
-:443 31.141.222.222 - - [13/Jun/2026:19:08:14 +0200] - "POST /xmlrpc.php HTTP/1.1" 404 6439 "-" "Mozilla/5.0 (Windows NT 6.2; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/85.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐ฉ๐ช
konseptit
2026-06-13 12:49:51
(3 days ago)
(wordpress) Failed wordpress login from 31.141.222.222 (TR/Tรผrkiye/-)
Brute-Force
๐จ๐ญ
4server
2026-06-13 12:19:18
(3 days ago)
[SatJun1314:19:13.3752902026][security2:error][pid1082752:tid1083158][client31.141.222.222:0]ModSecu ...
show more
[SatJun1314:19:13.3752902026][security2:error][pid1082752:tid1083158][client31.141.222.222:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"ruberticonsulting.ch\"][uri\"/xmlrpc.php\"][unique_id\"ai1KwTzNGwaua6vuxt6XCgAAAJI\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 12:13:24
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 31.141.222.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:13:18.347576 2026] [security2:error] [pid 21127:tid 21138] [client 31.141.222.222:59045] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rubenluis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rubenluis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai1JXgFgop3DH0yX-u6w3QAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack