๐บ๐ธ
TPI-Abuse
2026-06-16 07:00:35
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 03:00:27.357549 2026] [security2:error] [pid 18573:tid 18573] [client 76.13.138.71:34690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.earthtwoworkshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.earthtwoworkshop.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "ajD0i9XjGE1l0Ficq2iRWwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 00:24:28
(23 hours ago)
76.13.138.71 - - > www.bbaccademia.it [16/Jun/2026:02:24:25 +0200] "POST /xmlrpc.php HTTP/1.1" 403 1 ...
show more
76.13.138.71 - - > www.bbaccademia.it [16/Jun/2026:02:24:25 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:42.0) Gecko/20100101 Firefox/42.0" "-"
76.13.138.71 - - > www.bbaccademia.it [16/Jun/2026:02:24:25 +0200] "POST /wp-login.php HTTP/1.1" 200 1963 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" "-"
76.13.138.71 - - > www.bbaccademia.it [16/Jun/2026:02:24:26 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0" "-"
76.13.138.71 - - > www.bbaccademia.it [16/Jun/2026:02:24:27 +0200] "POST /wp-login.php HTTP/1.1" 200 1963 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0" "-"
76.13.138.71 - - > www.bbaccademia.it [16/Jun/2026:02:24:27 +0200] "POST /xmlrpc.php HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0" "-"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 10:22:59
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 06:22:51.906968 2026] [security2:error] [pid 22300:tid 22419] [client 76.13.138.71:33718] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.koalacogs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.koalacogs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_SeynLbWQ7LG-GcK7PDgAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:09:21
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:09:13.118983 2026] [security2:error] [pid 9082:tid 9082] [client 76.13.138.71:57258] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.investorsfundingusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.investorsfundingusa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai966aKMcyWR0_V4HHiehAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
reznekcs
2026-06-14 21:55:35
(2 days ago)
F2B wordpress ban. Logs: 76.13.138.71 - - [14/Jun/2026:23:55:22 +0200] "POST /xmlrpc.php HTTP/1.1" 2 ...
show more
F2B wordpress ban. Logs: 76.13.138.71 - - [14/Jun/2026:23:55:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0"
76.13.138.71 - - [14/Jun/2026:23:55:34 +0200] "POST /wp-login.php HTTP/1.1" 200 3809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 20:39:15
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 16:39:08.230096 2026] [security2:error] [pid 32734:tid 32734] [client 76.13.138.71:47308] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.baselinesc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.baselinesc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai8RbI5KROtW6mdYTX_FJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 10:07:11
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:07:07.939448 2026] [security2:error] [pid 26741:tid 26741] [client 76.13.138.71:44644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.peacecampus.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.peacecampus.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ai59S7ZXX6iDwONS5-LHCAAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-14 05:34:12
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 01:54:51
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 21:54:45.524793 2026] [security2:error] [pid 2570:tid 2570] [client 76.13.138.71:38066] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.97films.media|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.97films.media"] [uri "/wp-json/wp/v2/users"] [unique_id "ai4J5cPczB_cJ3xgFw39TgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 01:09:36
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 21:09:33.157736 2026] [security2:error] [pid 5987:tid 5987] [client 76.13.138.71:36066] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.consolidatedoperationsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.consolidatedoperationsgroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai3_TbU4k05yv2WNVsQlpgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 19:10:07
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 15:09:59.482159 2026] [security2:error] [pid 5411:tid 5411] [client 76.13.138.71:49060] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.disio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.disio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai2rB6xD3MBzdutR66oIhAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 16:16:26
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 12:16:21.802415 2026] [security2:error] [pid 31817:tid 31895] [client 76.13.138.71:46658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||byandlarge.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "byandlarge.nl"] [uri "/wp-json/wp/v2/users"] [unique_id "ai2CVZ20mL4_29bYy8FexAAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 13:46:06
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET / HTTP/1.1, GET /wp-json/wp/v ...
show more
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET / HTTP/1.1, GET /wp-json/wp/v2/users HTTP/1.1, POST /wp-login.php HTTP/1.1, GET /?author=1 HTTP/1.1, GET /?author=3 HTTP/1.1, GET /?author=2 HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 04:18:50
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 76.13.138.71 (srv1320778.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 00:18:46.189387 2026] [security2:error] [pid 30008:tid 30008] [client 76.13.138.71:34556] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.tonydelov.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.tonydelov.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aizaJrFxqxz4zjx3oRsrZQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Dolphi
2026-06-12 14:30:03
(4 days ago)
Excessive POST /wp-login.php requests
Brute-Force
Web App Attack