๐ฉ๐ช
4server
2026-05-14 00:29:05
(3 months ago)
[ThuMay1402:29:00.1845692026][security2:error][pid2466521:tid2466560][client45.148.124.103:0]ModSecu ...
show more
[ThuMay1402:29:00.1845692026][security2:error][pid2466521:tid2466560][client45.148.124.103:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"feldenkraisticino.ch\"][uri\"/xmlrpc.php\"][unique_id\"agUXTCQktrwQxBw8deg_EAAAAEI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-05-11 23:15:09
(3 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-04-21 00:54:05
(4 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-04-17 12:13:28
(4 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
kosada.com
2026-04-17 10:47:01
(4 months ago)
Web vulnerability probing: /wp-json/wp/v2/users
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 02:12:20
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 22:12:14.215831 2026] [security2:error] [pid 2929298:tid 2929298] [client 45.148.124.103:59239] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||billthompsons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "billthompsons.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad7z_jEAh6bsw88CNt0LZQAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-04-12 19:24:51
(4 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 14:16:15
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 10:16:07.923995 2026] [security2:error] [pid 4946:tid 4946] [client 45.148.124.103:19589] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thomasandross.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thomasandross.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adEdJ6qLz8mx1XyeG-apYgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 16:41:05
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 12:40:58.109944 2026] [security2:error] [pid 26809:tid 26809] [client 45.148.124.103:55637] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coopstehedwidge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coopstehedwidge.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acv5Gtl6Lcc6AdK67VOuXgAAACQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
windowsforum
2026-03-31 12:09:18
(4 months ago)
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, username=RefugioOld
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-29 17:28:12
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 13:28:06.925924 2026] [security2:error] [pid 11758:tid 11758] [client 45.148.124.103:63321] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tedharris.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aclhJmH7OL2k45YRChIIcgAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 18:40:16
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 14:40:11.571110 2026] [security2:error] [pid 18207:tid 18207] [client 45.148.124.103:25637] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paintriver.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paintriver.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acggi-H1C-BYcEBboe2gJQAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 12:11:39
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 08:11:31.473656 2026] [security2:error] [pid 8791:tid 8791] [client 45.148.124.103:19813] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alan-ip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alan-ip.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acfFc-SyvfttwvDpX920-QAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-03-26 01:46:55
(5 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
nationaleventpros.com
2026-03-21 21:46:41
(5 months ago)
WordPress login attempt
Brute-Force