Anonymous
2026-06-21 10:44:05
(3 hours ago)
(XMLRPC) WP XMLPRC Attack 82.154.116.98 (PT/Portugal/bl5-116-98.dsl.telepac.pt): 5 in the last 3600 ...
show more
(XMLRPC) WP XMLPRC Attack 82.154.116.98 (PT/Portugal/bl5-116-98.dsl.telepac.pt): 5 in the last 3600 secs; Ports: *; Direction: 1
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-21 04:52:04
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 00:51:55.565467 2026] [security2:error] [pid 23582:tid 23582] [client 82.154.116.98:60350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.silalaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.silalaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdt62hggREV_yhZDdthOQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-19 17:12:03
(1 day ago)
Bot / scanning and/or hacking attempts: GET /?author=3 HTTP/1.1, POST /xmlrpc.php HTTP/1.1, GET /aut ...
show more
Bot / scanning and/or hacking attempts: GET /?author=3 HTTP/1.1, POST /xmlrpc.php HTTP/1.1, GET /author/admin/ HTTP/1.1, GET /?author=1 HTTP/1.1, GET /wp-json/wp/v2/users HTTP/1.1, POST /wp-login.php HTTP/1.1, GET /?author=2 HTTP/1.1, GET / HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 09:33:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 05:33:39.917901 2026] [security2:error] [pid 29226:tid 29226] [client 82.154.116.98:52538] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.earthtwoworkshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.earthtwoworkshop.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "ajUM86HV3zocKpELdAMrpwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-19 08:46:02
(2 days ago)
trying wp-login.php/xmlrpc.php 44 times in 1 minutes
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 12:07:16
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 08:07:12.050675 2026] [security2:error] [pid 7294:tid 7294] [client 82.154.116.98:45994] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nationalenq.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nationalenq.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajPfcMuQNZBgLdtC6Syx9AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 09:37:34
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 05:37:28.760148 2026] [security2:error] [pid 5626:tid 5626] [client 82.154.116.98:40614] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.magacine.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.magacine.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "ajO8WLiANq1kIP2gBWZMWAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 06:22:20
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 02:22:12.310285 2026] [security2:error] [pid 32293:tid 32293] [client 82.154.116.98:43886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.coyotebytes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.coyotebytes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajOOlB-0eZSDZ_mBcwweNgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-17 22:32:19
(3 days ago)
[redacted] 82.154.116.98 - - [18/Jun/2026:00:32:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 248 "-" "M ...
show more
[redacted] 82.154.116.98 - - [18/Jun/2026:00:32:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 248 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0"
[redacted] 82.154.116.98 - - [18/Jun/2026:00:32:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 248 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
[redacted] 82.154.116.98 - - [18/Jun/2026:00:32:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 248 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:51.0) Gecko/20100101 Firefox/51.0"
[redacted] 82.154.116.98 - - [18/Jun/2026:00:32:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 248 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:86.0) Gecko/20100101 Firefox/86.0"
[redacted] 82.154.116.98 - - [18/Jun/2026:00:32:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 248 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:42.0) Gecko/20100101 Firefox/42.0"
eternalbliss-psytran
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 21:28:07
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 17:28:04.003546 2026] [security2:error] [pid 17189:tid 17189] [client 82.154.116.98:50932] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pjvcds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pjvcds.com"] [uri "/wordpress/wp-json/wp/v2/users"] [unique_id "ajMRZPVB9D3WJmLVftanYQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 12:45:14
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 08:45:10.305540 2026] [security2:error] [pid 31122:tid 31157] [client 82.154.116.98:52448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coasterdvdsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coasterdvdsonline.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajKW1sNeEG_vPs18OmviUQAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 07:41:33
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 03:41:30.441541 2026] [security2:error] [pid 23280:tid 23280] [client 82.154.116.98:43360] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.comicpreservation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.comicpreservation.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajJPqmLD8UAm1VwQkkbHUwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
ycoskun41
2026-06-17 00:47:54
(4 days ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 22:59:01
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 18:58:56.330271 2026] [security2:error] [pid 23588:tid 23588] [client 82.154.116.98:46002] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.avalderlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.avalderlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajHVMKmEt3UZ-qmrkMwmNwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 21:50:43
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 82.154.116.98 (bl5-116-98.dsl.telepac.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 17:50:39.736604 2026] [security2:error] [pid 12195:tid 12195] [client 82.154.116.98:35366] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fatcaverecords.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fatcaverecords.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajHFL-y8F9VdnFNVJ4nGAgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack