๐จ๐ญ
Peter-Johann Sarbach
2026-06-04 04:27:38
(2 hours ago)
Hacking website
Hacking
๐บ๐ธ
xmission.com
2026-06-03 10:48:03
(19 hours ago)
41.76.213.108 - - [03/Jun/2026:04:48:03 -0600] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 ...
show more
41.76.213.108 - - [03/Jun/2026:04:48:03 -0600] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 09:12:37
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): ...
show more
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 05:12:31.527861 2026] [security2:error] [pid 9265:tid 9265] [client 41.76.213.108:49470] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gabbyspetnanny.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gabbyspetnanny.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah_v_2VJuUSW7_2iE8vpwgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 08:16:10
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): ...
show more
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 04:16:03.102041 2026] [security2:error] [pid 24046:tid 24046] [client 41.76.213.108:35958] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "truthsabouthealthcare.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah_iwzVdEQ_Ut4secFnsKwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 08:05:52
(22 hours ago)
2026-06-03T10:05:51.382112+02:00 zanati wp(sahpa.co.za)[3235279]: Blocked user enumeration attempt f ...
show more
2026-06-03T10:05:51.382112+02:00 zanati wp(sahpa.co.za)[3235279]: Blocked user enumeration attempt from 41.76.213.108
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 07:30:24
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): ...
show more
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 03:30:19.981480 2026] [security2:error] [pid 19259:tid 19259] [client 41.76.213.108:35598] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||citrineartstudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "citrineartstudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah_YCzJlL4f4hWCxeKxiRQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-03 07:03:13
(23 hours ago)
paulshipley.com.au:443 41.76.213.108 - - [03/Jun/2026:17:03:10 +1000] "GET /?author=18 HTTP/1.1" 404 ...
show more
paulshipley.com.au:443 41.76.213.108 - - [03/Jun/2026:17:03:10 +1000] "GET /?author=18 HTTP/1.1" 404 232504 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 06:58:18
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): ...
show more
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:58:14.967558 2026] [security2:error] [pid 1756:tid 1756] [client 41.76.213.108:48240] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||justiart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "justiart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah_QhsuqyNklvYSzztUQowAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-03 06:47:15
(23 hours ago)
indigi-print-merch.com.au:443 41.76.213.108 - - [03/Jun/2026:16:47:12 +1000] "GET /?author=2 HTTP/1. ...
show more
indigi-print-merch.com.au:443 41.76.213.108 - - [03/Jun/2026:16:47:12 +1000] "GET /?author=2 HTTP/1.1" 404 98487 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 06:11:06
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): ...
show more
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:10:57.901204 2026] [security2:error] [pid 7836:tid 7836] [client 41.76.213.108:46528] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||havilahmalone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "havilahmalone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah_FcZHwzrdsu7pxVqTuEQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-03 06:07:40
(1 day ago)
levellapromotions.com.au:443 41.76.213.108 - - [03/Jun/2026:16:07:36 +1000] "GET /?author=18 HTTP/1. ...
show more
levellapromotions.com.au:443 41.76.213.108 - - [03/Jun/2026:16:07:36 +1000] "GET /?author=18 HTTP/1.1" 404 346531 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36, Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 05:41:34
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): ...
show more
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:41:25.750758 2026] [security2:error] [pid 6346:tid 6346] [client 41.76.213.108:33988] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||harvestfrc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "harvestfrc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah--hYRzzYnT9n5Q9ZWLgwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
eliosbrocchi
2026-06-03 05:10:15
(1 day ago)
2026-06-03T07:10:13.589270+02:00 thunderchild wordpress(www.crislio.com)[848246]: Immediately block ...
show more
2026-06-03T07:10:13.589270+02:00 thunderchild wordpress(www.crislio.com)[848246]: Immediately block connections from 41.76.213.108
...
show less
VPN IP
Anonymous
2026-06-03 05:10:05
(1 day ago)
Bot / scanning and/or hacking attempts: [0/0] done, [1/1] done, POST /xmlrpc.php HTTP/2.0
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 04:52:42
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): ...
show more
(mod_security) mod_security (id:225170) triggered by 41.76.213.108 (indetailserver.dedicated.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 00:52:34.971598 2026] [security2:error] [pid 20011:tid 20011] [client 41.76.213.108:37020] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||smoothiessoupssalads.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "smoothiessoupssalads.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah-zEgfAfNwSVzcOQKSbXQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack