๐ซ๐ท
Jean Valjean
2026-02-13 13:18:48
(7 months ago)
Fail2ban Caboom : wp-login.php Bruteforce
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-15 17:36:51
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 12:36:47.814004 2026] [security2:error] [pid 2414968:tid 2414986] [client 69.16.157.113:60406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||potterpuppetpals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "potterpuppetpals.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWklrwo2Eeww7p9_20Xt7AAAAM4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-15 17:21:20
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 12:21:13.602635 2026] [security2:error] [pid 1416:tid 1416] [client 69.16.157.113:46618] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chezlubacov.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chezlubacov.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aWkiCcIxRNgAxi-VLpOaNwAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-15 16:11:09
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 11:11:06.716455 2026] [security2:error] [pid 6337:tid 6337] [client 69.16.157.113:56048] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||madbanana.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "madbanana.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWkRmg6scqIWNC-7kCJRMgAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-15 07:37:50
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 02:37:45.315809 2026] [security2:error] [pid 19100:tid 19100] [client 69.16.157.113:39022] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||curts.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "curts.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aWiZSWqPp8ciTDcnnIKfIwAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
oisecnet
2026-01-11 22:01:51
(8 months ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-01-11. 4 requests from this I ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-01-11. 4 requests from this IP.
show less
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-11 02:59:06
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 10 21:59:01.087784 2026] [security2:error] [pid 23081:tid 23081] [client 69.16.157.113:52348] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sahinozalit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sahinozalit.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWMR9SOrePFsCRiruZG-YgAAACk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-11 00:09:07
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 10 19:09:03.165584 2026] [security2:error] [pid 6876:tid 6876] [client 69.16.157.113:48384] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||randyshelly.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "randyshelly.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWLqH5PnYCqXzzJPk54AaQAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-01-07 12:15:39
(8 months ago)
69.16.157.113 - - [07/Jan/2026:06:15:10 -0600] "POST /xmlrpc.php HTTP/1.1" 200 2734 "-" "Apache-Http ...
show more
69.16.157.113 - - [07/Jan/2026:06:15:10 -0600] "POST /xmlrpc.php HTTP/1.1" 200 2734 "-" "Apache-HttpClient/4.5.13 (Java/11.0.29)"
69.16.157.113 - - [07/Jan/2026:06:15:12 -0600] "POST /xmlrpc.php HTTP/1.1" 200 2808 "-" "Apache-HttpClient/4.5.13 (Java/11.0.29)"
69.16.157.113 - - [07/Jan/2026:06:15:34 -0600] "POST /xmlrpc.php HTTP/1.1" 200 2807 "-" "Apache-HttpClient/4.5.13 (Java/11.0.29)"
69.16.157.113 - - [07/Jan/2026:06:15:36 -0600] "POST /xmlrpc.php HTTP/1.1" 200 2808 "-" "Apache-HttpClient/4.5.13 (Java/11.0.29)"
69.16.157.113 - - [07/Jan/2026:06:15:38 -0600] "GET /wp-login.php HTTP/1.1" 200 4555 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-01-01 23:42:31
(8 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 20:45:23
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 15:45:20.021853 2025] [security2:error] [pid 12383:tid 12383] [client 69.16.157.113:36660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||therhclan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "therhclan.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aVWLYM7Q__WY04kgFdp8GwAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2025-12-31 19:49:33
(8 months ago)
2025/12/31 19:49:14 [error] 3295562#3295562: *201457750 access forbidden by rule, client: 69.16.157. ...
show more
2025/12/31 19:49:14 [error] 3295562#3295562: *201457750 access forbidden by rule, client: 69.16.157.113, server: infinsa.com, request: "POST /xmlrpc.php HTTP/2.0", host: "infinsa.com"
2025/12/31 19:49:16 [error] 3295567#3295567: *201457722 access forbidden by rule, client: 69.16.157.113, server: infinsa.com, request: "GET /wp-login.php HTTP/2.0", host: "infinsa.com", referrer: "https://www.google.com"
2025/12/31 19:49:31 [error] 3295563#3295563: *201458124 access forbidden by rule, client: 69.16.157.113, server: infinsa.com, request: "GET /wp-login.php HTTP/2.0", host: "infinsa.com", referrer: "https://www.google.com"
...
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2025-12-31 06:54:25
(8 months ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-30 22:56:44
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 17:56:40.667551 2025] [security2:error] [pid 13958:tid 13958] [client 69.16.157.113:38582] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tiley.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tiley.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aVRYqPRplm-Eeiw-qRPS-gAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-30 20:02:06
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 69.16.157.113 (69-16-157-113.lin.as62651.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 15:01:52.731208 2025] [security2:error] [pid 28131:tid 28131] [client 69.16.157.113:33654] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mmailbox.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mmailbox.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aVQvsBXzW-Vnq5mb_veDrQAAAC0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack