๐ช๐ธ
librebit
2026-08-15 00:55:13
(1 week ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 21:55:17
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 5.181.170.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 5.181.170.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 17:55:02.265341 2026] [security2:error] [pid 30950:tid 30950] [client 5.181.170.124:56619] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tedharris.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiH0NvPssmScJ8ownryshAAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-05-31 16:43:11
(2 months ago)
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Web App Attack
Anonymous
2026-05-25 23:37:25
(2 months ago)
Blocked by ModSec and CSF
Port Scan
๐ฆ๐บ
screwlooseit.com.au
2026-05-18 16:33:03
(3 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
RU/Russia/-
Web App Attack
๐จ๐ฟ
ptlab
2026-04-21 04:49:57
(4 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-18 01:39:32
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 5.181.170.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 5.181.170.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 21:39:17.936296 2026] [security2:error] [pid 1530351:tid 1530351] [client 5.181.170.124:19489] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||intersession.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "intersession.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aeLgxQ9Y6psP0VAwZ-N8pQAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-03-21 18:45:18
(5 months ago)
Try to access /xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob
2026-03-20 01:00:41
(5 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-03-19 16:40:39
(5 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
myagent.site
2026-03-17 17:39:53
(5 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฉ๐ช
LRob
2026-03-17 12:30:10
(5 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 18:49:43
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 5.181.170.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 5.181.170.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:49:28.556199 2026] [security2:error] [pid 21673:tid 21673] [client 5.181.170.124:40565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grasslakepizzatime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grasslakepizzatime.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJxOAhHSiOoKU4VbO-SYgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 16:39:26
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 5.181.170.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 5.181.170.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 11:39:09.354899 2025] [security2:error] [pid 11275:tid 11275] [client 5.181.170.124:29881] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dwars.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dwars.net"] [uri "/"] [unique_id "aRisrTb5gEwdl_ueJ7t6hQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
lp
2025-10-25 18:20:49
(9 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 5.181.170.124
2025-10-25T19:58:37+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 5.181.170.124
2025-10-25T19:58:37+02:00 vpn Access-Reject 'cisco' station: 5.181.170.124 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack