๐บ๐ธ
TPI-Abuse
2026-06-14 18:46:10
(8 minutes ago)
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 14:46:02.794678 2026] [security2:error] [pid 16094:tid 16094] [client 79.112.96.34:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pixacast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pixacast.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai726vTpZlcx9FaPFPuaMgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-14 18:32:40
(22 minutes ago)
1.047 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-14 18:28:54
(25 minutes ago)
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 14:28:48.412906 2026] [security2:error] [pid 916:tid 938] [client 79.112.96.34:33194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ward-bergerhouse.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ward-bergerhouse.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai7y4CU5MMW3BmRt7PL3dwAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 18:12:16
(42 minutes ago)
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 14:12:10.582596 2026] [security2:error] [pid 24330:tid 24330] [client 79.112.96.34:43842] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vespaitaliancafe.matteozacchino.dev|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vespaitaliancafe.matteozacchino.dev"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai7u-g9X7WhyL9iB2bhLZQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-14 18:00:06
(54 minutes ago)
Wordfence waf block on registrymatters
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-06-14 17:54:06
(1 hour ago)
2026-06-14T19:54:05.458636+02:00 ipoac.nl wordpress(-)-: XML-RPC authentication failure for-from 79. ...
show more
2026-06-14T19:54:05.458636+02:00 ipoac.nl wordpress(-)-: XML-RPC authentication failure for-from 79.112.96.34
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 17:47:44
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 13:47:36.839470 2026] [security2:error] [pid 23049:tid 23049] [client 79.112.96.34:48380] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nwuoregon.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nwuoregon.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai7pOCoNRpG1DlGB9HAU8QAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-14 17:39:16
(1 hour ago)
(wordpress) Failed wordpress login from 79.112.96.34 (ES/Spain/79-112-96-34.digimobil.es)
Brute-Force
๐ฒ๐น
Malta
2026-06-14 17:11:46
(1 hour ago)
79.112.96.34 - - [14/Jun/2026:19:11:46 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linux ...
show more
79.112.96.34 - - [14/Jun/2026:19:11:46 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 17:06:13
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 13:06:09.458770 2026] [security2:error] [pid 9659:tid 9659] [client 79.112.96.34:46782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bfpsamoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bfpsamoa.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai7fgQaz0snk-Vcq4XyTJAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-06-14 16:45:36
(2 hours ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-14 16:15:05
(2 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-06-14 16:06:04
(2 hours ago)
79.112.96.34 - - [14/Jun/2026:10:06:04 -0600] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 ( ...
show more
79.112.96.34 - - [14/Jun/2026:10:06:04 -0600] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 15:52:21
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:52:14.382969 2026] [security2:error] [pid 24407:tid 24425] [client 79.112.96.34:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.mindgardens.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.mindgardens.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai7OLqI71X_ztpsSXdrTpgAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 15:24:16
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 79.112.96.34 (79-112-96-34.digimobil.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:24:12.859497 2026] [security2:error] [pid 12465:tid 12465] [client 79.112.96.34:55042] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doublenaughtspycar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doublenaughtspycar.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai7HnNv-MkYm7t6C1DFVxwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack