πΊπΈ
mnsf
2025-07-23 01:05:48
(10 months ago)
Xmlrpc Caught (8)
Brute-Force
Web App Attack
π©πͺ
LRob.fr
2025-07-17 04:00:19
(10 months ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
π©πͺ
Ba-Yu
2025-07-17 01:34:54
(10 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
π©πͺ
LRob.fr
2025-07-16 18:30:18
(10 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
π©πͺ
stinpriza
2025-07-15 23:08:49
(10 months ago)
Web App Attack
Web App Attack
π©πͺ
LRob.fr
2025-07-14 21:15:19
(10 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
π¬π§
Swiptly
2025-07-14 17:31:14
(10 months ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2025-07-13 01:22:46
(10 months ago)
(wordpress) Failed wordpress login from 5.100.153.224 (US/United States/-/-/bhuk-pp-wb1.webhostbox.n ...
show more
(wordpress) Failed wordpress login from 5.100.153.224 (US/United States/-/-/bhuk-pp-wb1.webhostbox.net/[redacted])
show less
Brute-Force
π©πͺ
stinpriza
2025-07-12 18:38:42
(10 months ago)
Web App Attack
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-09 05:59:54
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 5.100.153.224 (bhuk-pp-wb1.webhostbox.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 5.100.153.224 (bhuk-pp-wb1.webhostbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 09 01:59:46.505338 2025] [security2:error] [pid 14691:tid 14691] [client 5.100.153.224:58675] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grupoimaginarte.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grupoimaginarte.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aG4FUoAfCFkixFCgf9-c9AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-08 21:39:32
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 5.100.153.224 (bhuk-pp-wb1.webhostbox.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 5.100.153.224 (bhuk-pp-wb1.webhostbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 17:39:29.711614 2025] [security2:error] [pid 883:tid 883] [client 5.100.153.224:50564] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||caribbeancoralinstitute.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "caribbeancoralinstitute.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aG2QEZxWIQiMpRQwbgU7nwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SCHAPPY
2025-07-08 16:10:33
(11 months ago)
Wordpress attack: user enumeration attempt detected.
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-08 15:00:53
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 5.100.153.224 (bhuk-pp-wb1.webhostbox.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 5.100.153.224 (bhuk-pp-wb1.webhostbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 11:00:45.675616 2025] [security2:error] [pid 5703:tid 5703] [client 5.100.153.224:61815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||franzexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "franzexpress.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aG0ynSEyGkZlb-HdFU_yrQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-07 16:15:44
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 5.100.153.224 (bhuk-pp-wb1.webhostbox.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 5.100.153.224 (bhuk-pp-wb1.webhostbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 07 12:15:40.835349 2025] [security2:error] [pid 13455:tid 13455] [client 5.100.153.224:56131] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||engineeringarts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "engineeringarts.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aGvyrP_Ddf3j5L9DQxEAtgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2025-07-05 21:15:13
(11 months ago)
(wordpress) Failed wordpress login from 5.100.153.224 (US/United States/-/-/bhuk-pp-wb1.webhostbox.n ...
show more
(wordpress) Failed wordpress login from 5.100.153.224 (US/United States/-/-/bhuk-pp-wb1.webhostbox.net/[redacted])
show less
Brute-Force