๐ฉ๐ช
LRob.fr
2026-06-24 22:45:06
(13 minutes ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-06-24 19:00:56
(3 hours ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-23 22:32:37
(1 day ago)
Brute-Force
Web App Attack
Anonymous
2026-06-23 00:25:58
(1 day ago)
CMS (WordPress or Joomla) brute force attempt.
Brute-Force
๐ฉ๐ช
konseptit
2026-06-22 15:29:25
(2 days ago)
(wordpress) Failed wordpress login from 45.92.109.120 (FR/France/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-22 15:13:32
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 11:13:25.244887 2026] [security2:error] [pid 419:tid 419] [client 45.92.109.120:51418] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.hotpay.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.hotpay.co"] [uri "/wp-json/wp/v2/users"] [unique_id "ajlRFaUB-YJbPG8-VkaEvQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 08:22:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 04:22:39.730272 2026] [security2:error] [pid 381:tid 381] [client 45.92.109.120:44222] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.indiahouseportland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.indiahouseportland.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajjwz_JJV7gUOuTD2dfJRgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 08:12:33
(2 days ago)
45.92.109.120 - - > www.allacasadilucia.it [22/Jun/2026:10:12:31 +0200] "POST /xmlrpc.php HTTP/1.1" ...
show more
45.92.109.120 - - > www.allacasadilucia.it [22/Jun/2026:10:12:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:41.0) Gecko/20100101 Firefox/41.0" "-"
45.92.109.120 - - > www.allacasadilucia.it [22/Jun/2026:10:12:32 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0" "-"
45.92.109.120 - - > www.allacasadilucia.it [22/Jun/2026:10:12:32 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0" "-"
45.92.109.120 - - > www.allacasadilucia.it [22/Jun/2026:10:12:32 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" "-"
45.92.109.120 - - > www.allacasadilucia.it [22/Jun/2026:10:12:32 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0" "-"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-21 22:41:12
(3 days ago)
(wordpress) Failed wordpress login from 45.92.109.120 (FR/France/-): (CF_ENABLE)
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-06-20 22:31:09
(4 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-19 22:30:50
(5 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 02:50:25
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 22:50:17.362470 2026] [security2:error] [pid 15234:tid 15234] [client 45.92.109.120:54424] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.casapapayasanmiguel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.casapapayasanmiguel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajSuaQGBO-DPfp1M_Mfp0wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-18 21:22:57
(6 days ago)
(wp_login_try) srv104 WP Login Attempt 45.92.109.120 (FR/France/-): 10 in the last 3600 secs; Ports: ...
show more
(wp_login_try) srv104 WP Login Attempt 45.92.109.120 (FR/France/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 14:17:45
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 10:17:40.391530 2026] [security2:error] [pid 19715:tid 19715] [client 45.92.109.120:39550] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bickleton.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajP-BOvd1SXiLal_Knk-kAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 04:20:36
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.92.109.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 00:20:32.684740 2026] [security2:error] [pid 24996:tid 24996] [client 45.92.109.120:38136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.thomasgardner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.thomasgardner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajNyEOmLl6rOpnDRemD-nQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack