๐บ๐ธ
TPI-Abuse
2026-06-15 07:23:06
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:22:59.411530 2026] [security2:error] [pid 12046:tid 12046] [client 51.255.167.208:48252] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jazziiafoundation.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai-oUy0oCol8XDND_BZGUAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-14 18:53:01
(21 hours ago)
Excessive 404/403 errors
Brute-Force
๐ธ๐ช
vaia.cloud
2026-06-14 16:04:01
(1 day ago)
trying wp-login.php/xmlrpc.php 80 times in 1 minutes
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 05:25:35
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:25:29.189313 2026] [security2:error] [pid 8513:tid 8513] [client 51.255.167.208:52246] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.asapstarsmogcheck.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.asapstarsmogcheck.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai47SXpLI4YqJJGWSgR42QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 19:18:43
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 15:18:37.746897 2026] [security2:error] [pid 6901:tid 6901] [client 51.255.167.208:60850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sizefinder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sizefinder.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai2tDZhOOkVipwDcR3KpfAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 01:49:00
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 21:48:56.332414 2026] [security2:error] [pid 2559:tid 2559] [client 51.255.167.208:53348] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.whodatnation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.whodatnation.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiy3CLQH1KQE6R3Czd_G5wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 15:25:46
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 11:25:42.140199 2026] [security2:error] [pid 21745:tid 21745] [client 51.255.167.208:49336] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.blacksheepoffroad.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiwk9igFwbpU5eludSe2QQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 13:45:57
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 09:45:53.389813 2026] [security2:error] [pid 25049:tid 25049] [client 51.255.167.208:52160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.joeordie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.joeordie.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiwNkVcY-E9-vrwKlZjNrgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-06-11 07:46:46
(4 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 07:46:20
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 03:46:16.356715 2026] [security2:error] [pid 30535:tid 30535] [client 51.255.167.208:60758] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.investorsfundingusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.investorsfundingusa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aipnyBY5Mt73bSJ8q_Gj6gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 04:44:31
(4 days ago)
[redacted] 51.255.167.208 - - [11/Jun/2026:06:44:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" " ...
show more
[redacted] 51.255.167.208 - - [11/Jun/2026:06:44:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0"
[redacted] 51.255.167.208 - - [11/Jun/2026:06:44:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0"
[redacted] 51.255.167.208 - - [11/Jun/2026:06:44:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0"
[redacted] 51.255.167.208 - - [11/Jun/2026:06:44:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0"
[redacted] 51.255.167.208 - - [11/Jun/2026:06:44:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0"
[redacted] 51.255
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 01:28:13
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 51.255.167.208 (208.ip-51-255-167.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 21:28:08.781050 2026] [security2:error] [pid 7480:tid 7480] [client 51.255.167.208:41596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.badgerkelley.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.badgerkelley.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aioPKPS2co1PHfBLkP_a9gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-02-09 21:06:27
(4 months ago)
(wordpress) Failed wordpress login from 51.255.167.208 (FR/France/-/-/208.ip-51-255-167.eu/[redacted ...
show more
(wordpress) Failed wordpress login from 51.255.167.208 (FR/France/-/-/208.ip-51-255-167.eu/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐ฉ๐ช
karger
2026-02-09 09:11:41
(4 months ago)
Wordpress attack - soft filter
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-02-07 12:57:58
(4 months ago)
Try to access /xmlrpc.php
Web App Attack