๐ซ๐ท
masterguru
2026-07-03 03:50:44
(1 month ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (88020-195)
Hacking
๐บ๐ธ
lostswordfish.com
2026-06-25 13:10:06
(1 month ago)
Wordfence waf block on wp20190711M4
Web App Attack
๐ฉ๐ช
LRob
2026-06-25 09:45:11
(1 month ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2026-06-23 15:27:32
(1 month ago)
[redacted] 51.83.154.40 - - [23/Jun/2026:17:27:30 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mo ...
show more
[redacted] 51.83.154.40 - - [23/Jun/2026:17:27:30 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0"
[redacted] 51.83.154.40 - - [23/Jun/2026:17:27:30 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
[redacted] 51.83.154.40 - - [23/Jun/2026:17:27:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:82.0) Gecko/20100101 Firefox/82.0"
[redacted] 51.83.154.40 - - [23/Jun/2026:17:27:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 51.83.154.40 - - [23/Jun/2026:17:27:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:63.0) Gecko/20100101 Firefox/63.0"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 10:20:01
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 51.83.154.40 (vps-b626b7fe.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 51.83.154.40 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 06:19:57.437999 2026] [security2:error] [pid 5060:tid 5060] [client 51.83.154.40:41724] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bamedica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajpdzUmWjlWCDOCXvsvT6QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-23 05:04:24
(1 month ago)
(wordpress) Failed wordpress login from 51.83.154.40 (FR/France/vps-b626b7fe.vps.ovh.net): (CF_ENAB ...
show more
(wordpress) Failed wordpress login from 51.83.154.40 (FR/France/vps-b626b7fe.vps.ovh.net): (CF_ENABLE)
show less
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-06-22 22:33:38
(1 month ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 17:43:03
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 51.83.154.40 (vps-b626b7fe.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 51.83.154.40 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 13:42:58.738769 2026] [security2:error] [pid 32313:tid 32313] [client 51.83.154.40:47638] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bickleton.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajl0IjdF62srfZ21J9EJ3wAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-22 15:32:31
(1 month ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 12:32:51
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 51.83.154.40 (vps-b626b7fe.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 51.83.154.40 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 08:32:48.623027 2026] [security2:error] [pid 31954:tid 31954] [client 51.83.154.40:57798] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.riser-astrology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.riser-astrology.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkrcCZAwqrsLHQpXOPs_QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-22 12:04:18
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 11:59:34
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 51.83.154.40 (vps-b626b7fe.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 51.83.154.40 (vps-b626b7fe.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 07:59:29.389140 2026] [security2:error] [pid 14938:tid 14938] [client 51.83.154.40:48228] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "major33.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkjoVVWceQb1RhmtLI2FQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 07:53:20
(1 month ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TAY
2026-06-22 05:20:54
(1 month ago)
51.83.154.40 - - [22/Jun/2026:13:20:50 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5755 "-" "Mozilla/5.0 ...
show more
51.83.154.40 - - [22/Jun/2026:13:20:50 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5755 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0"
51.83.154.40 - - [22/Jun/2026:13:20:52 +0800] "POST /wp-login.php HTTP/1.1" 200 8090 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0"
51.83.154.40 - - [22/Jun/2026:13:20:53 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5755 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Brute-Force
๐ณ๐ฑ
Mangelot Hosting
2026-06-21 20:21:21
(1 month ago)
(modsecurity) srv102 ModSecurity 51.83.154.40 (PL/Poland/vps-b626b7fe.vps.ovh.net): 10 in the last 3 ...
show more
(modsecurity) srv102 ModSecurity 51.83.154.40 (PL/Poland/vps-b626b7fe.vps.ovh.net): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack