๐ฉ๐ช
F242
2026-07-29 01:04:00
(1 hour ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฉ๐ช
4server
2026-07-28 21:37:54
(5 hours ago)
[TueJul2823:37:49.0898602026][security2:error][pid665661:tid665778][client62.60.201.32:0]ModSecurity ...
show more
[TueJul2823:37:49.0898602026][security2:error][pid665661:tid665778][client62.60.201.32:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"gmint.ch\"][uri\"/xmlrpc.php\"][unique_id\"amkhLfQhlCm-dLf6IPmL2QAAANY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-07-28 04:58:48
(21 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 03:39:00
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name ...
show more
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 23:38:54.578937 2026] [security2:error] [pid 531639:tid 531639] [client 62.60.201.32:54566] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||creationorevolution.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "creationorevolution.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amgkTg0Wc1LKaGtM4vs_ugAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 03:00:07
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name ...
show more
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 23:00:02.420097 2026] [security2:error] [pid 2994648:tid 2994686] [client 62.60.201.32:40092] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dasperformance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dasperformance.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "amgbMlwT0A2ZW47FwTHwngAAAYY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 01:06:49
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name ...
show more
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 21:06:41.672797 2026] [security2:error] [pid 1799128:tid 1799128] [client 62.60.201.32:53122] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jellisonrepair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jellisonrepair.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amgAobIUsbF_SaFUy9PxdQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-28 00:05:09
(1 day ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 22:35:30
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name ...
show more
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:35:25.661645 2026] [security2:error] [pid 869124:tid 869124] [client 62.60.201.32:52526] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fivecentmiracle.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fivecentmiracle.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amfdLbQV8cp_g7WTH_ainQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 17:03:29
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name ...
show more
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:03:21.534652 2026] [security2:error] [pid 1467830:tid 1467830] [client 62.60.201.32:57654] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||matt-bechtel.neconebooks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "matt-bechtel.neconebooks.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amePWUImuq_7xXhGcWxD8wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 16:47:04
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name ...
show more
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 12:46:59.214038 2026] [security2:error] [pid 39526:tid 39526] [client 62.60.201.32:39772] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||harwoodmechanical.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "harwoodmechanical.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ameLg_AK12OSRt6yBnzvLgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:24:29
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name ...
show more
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:24:22.468929 2026] [security2:error] [pid 3788110:tid 3788110] [client 62.60.201.32:38626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mayiasteadman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mayiasteadman.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amd4Jm9CCPPqWCaX8INRgwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 12:52:28
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name ...
show more
(mod_security) mod_security (id:225170) triggered by 62.60.201.32 (62.60.201.32.static.hostiran.name): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:52:22.714802 2026] [security2:error] [pid 1352449:tid 1352449] [client 62.60.201.32:45268] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bundrenfarmstn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bundrenfarmstn.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amdUhqLpUUXtftCugU8ZWgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-27 12:31:35
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-27 04:13:16
(1 day ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-27 01:59:30
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack