๐ต๐ฑ
wHosts
2026-06-28 11:30:47
(21 hours ago)
Blocked by Fail2Ban
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-06-28 10:47:09
(22 hours ago)
WordPress login attempt
Brute-Force
Anonymous
2026-06-28 08:34:56
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-28 03:45:05
(1 day ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-06-27 18:15:08
(1 day ago)
36.50.27.26 - [27/Jun/2026:21:15:08 +0300] "POST /xmlrpc.php HTTP/1.1" 403 8192 "-" "Mozilla/5.0 (Wi ...
show more
36.50.27.26 - [27/Jun/2026:21:15:08 +0300] "POST /xmlrpc.php HTTP/1.1" 403 8192 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
36.50.27.26 - - [27/Jun/2026:21:15:08 +0300] "POST /xmlrpc.php HTTP/1.1" 403 75 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
Web App Attack
๐บ๐ธ
cwytech
2026-06-26 22:45:40
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-06-25 07:31:28
(4 days ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
๐ท๐ด
INTEQ
2026-06-24 21:27:21
(4 days ago)
Web attack from 36.50.27.26
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 10:39:34
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 36.50.27.26 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 36.50.27.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 06:39:28.313249 2026] [security2:error] [pid 22929:tid 22929] [client 36.50.27.26:37658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.citizensforsanity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.citizensforsanity.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajpiYLxxt7meVq8jRZfQrAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 21:43:15
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 36.50.27.26 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 36.50.27.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 17:43:09.439044 2026] [security2:error] [pid 11958:tid 11958] [client 36.50.27.26:35676] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fritsknuf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fritsknuf.com"] [uri "/blog/wp-json/wp/v2/users"] [unique_id "ajmsbUCWSeShgW13TEF3WgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 04:38:39
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 36.50.27.26 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 36.50.27.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 00:38:32.211423 2026] [security2:error] [pid 3997:tid 3997] [client 36.50.27.26:47452] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rddeckerphotography.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rddeckerphotography.com"] [uri "/blog/wp-json/wp/v2/users"] [unique_id "ajdqyEHMWlyLB9DARqUd-gAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-16 21:26:30
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-13 22:29:24
(2 weeks ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-12 22:29:11
(2 weeks ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 10:05:49
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 36.50.27.26 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 36.50.27.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 06:05:42.109078 2026] [security2:error] [pid 12294:tid 12294] [client 36.50.27.26:36652] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ixd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ixd.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aivZ9jI5ADeZSzymUTbbqgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack