๐ซ๐ท
mail.avx.gr
2026-07-23 09:52:56
(2 days ago)
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 87.16.246.214 - - [23/Jul/2026:12:52:55 +0300] "PO ...
show more
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 87.16.246.214 - - [23/Jul/2026:12:52:55 +0300] "POST /xmlrpc.php HTTP/1.1" 404 808 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-07-23 09:51:29
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 08:59:50
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 87.16.246.214 (host-87-16-246-214.retail.teleco ...
show more
(mod_security) mod_security (id:225170) triggered by 87.16.246.214 (host-87-16-246-214.retail.telecomitalia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 04:59:46.319211 2026] [security2:error] [pid 2029320:tid 2029320] [client 87.16.246.214:53319] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||415test.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "415test.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amHYAuRI4l67qwyj1TVRzgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Hippoline
2026-07-22 21:34:40
(3 days ago)
[Wed Jul 22 23:30:00.755063 2026] [authz_core:error] [pid 17166] [client 87.16.246.214:62399] AH0163 ...
show more
[Wed Jul 22 23:30:00.755063 2026] [authz_core:error] [pid 17166] [client 87.16.246.214:62399] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
[Wed Jul 22 23:34:14.133208 2026] [authz_core:error] [pid 25068] [client 87.16.246.214:50599] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
[Wed Jul 22 23:34:31.536545 2026] [authz_core:error] [pid 19545] [client 87.16.246.214:50872] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
[Wed Jul 22 23:34:39.766532 2026] [authz_core:error] [pid 22190] [client 87.16.246.214:51009] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
[Wed Jul 22 23:34:39.970789 2026] [access_compat:error] [pid 25003] [client 87.16.246.214:51010] AH01797: client denied by server configuration: /var/www/hippoline.lu/web/xmlrpc.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 14:41:48
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 87.16.246.214 (host-87-16-246-214.retail.teleco ...
show more
(mod_security) mod_security (id:225170) triggered by 87.16.246.214 (host-87-16-246-214.retail.telecomitalia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 10:41:41.582976 2026] [security2:error] [pid 1159713:tid 1159713] [client 87.16.246.214:63183] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yogawithbubba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yogawithbubba.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amDWpaZPmukjYovZJ6hClAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
NotCool
2026-07-22 13:29:26
(3 days ago)
[7200] (ABUSIVEBOT,XMLRPC) Login failure/trigger from 87.16.246.214 (IT/Italy/host-87-16-246-214.ret ...
show more
[7200] (ABUSIVEBOT,XMLRPC) Login failure/trigger from 87.16.246.214 (IT/Italy/host-87-16-246-214.retail.telecomitalia.it): 50 in the last 3600 secs
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-22 09:02:40
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 87.16.246.214 (host-87-16-246-214.retail.teleco ...
show more
(mod_security) mod_security (id:225170) triggered by 87.16.246.214 (host-87-16-246-214.retail.telecomitalia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 05:02:35.803836 2026] [security2:error] [pid 6162:tid 6162] [client 87.16.246.214:56315] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nidusmbt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nidusmbt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amCHK8LRkIdPRNMJ3tn8CgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-07-21 21:35:36
(4 days ago)
Multiple attempts to attack Wordpress XMLRPC detected: access blocked.
Web App Attack
๐ฎ๐ฉ
zam
2026-07-21 16:06:58
(4 days ago)
87.16.246.214 - - [21/Jul/2026:16:06:56 +0000] "POST /xmlrpc.php HTTP/1.1" 403 239
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 09:54:29
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 87.16.246.214 (host-87-16-246-214.retail.teleco ...
show more
(mod_security) mod_security (id:225170) triggered by 87.16.246.214 (host-87-16-246-214.retail.telecomitalia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 05:54:24.452153 2026] [security2:error] [pid 17654:tid 17654] [client 87.16.246.214:62768] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fredlandia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fredlandia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al9B0LE9X5lC-nkWXo_CcAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack