Anonymous
2026-06-10 23:56:04
(18 hours ago)
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0"
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0"
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0"
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0"
[redacted] 91.198.89.37 - - [11/Jun/2026:01:56:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 91.198.89.37 - - [11/Jun/202
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 20:10:21
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:10:17.451446 2026] [security2:error] [pid 30890:tid 30890] [client 91.198.89.37:41780] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soundtrax.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ainEqdVqoqao7Y3oEyhMIQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-10 16:20:59
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
masterguru
2026-06-10 12:32:42
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack
๐ซ๐ท
dynamix
2026-06-09 15:29:14
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 23:46:06
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 19:46:00.590734 2026] [security2:error] [pid 4557:tid 4557] [client 91.198.89.37:43774] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mccompu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mccompu.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiYCuE6jrubCU4FcfsbfaAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 16:41:02
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 12:40:57.776965 2026] [security2:error] [pid 24315:tid 24315] [client 91.198.89.37:46856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiWfGSMQqAR_fim2YUgutgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 03:12:31
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 23:12:26.611845 2026] [security2:error] [pid 27701:tid 27701] [client 91.198.89.37:39268] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lahamradio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiThmkU_36oRz7I2_CjJiwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 19:18:58
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 15:18:53.166936 2026] [security2:error] [pid 17831:tid 17831] [client 91.198.89.37:52250] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stellabluesales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stellabluesales.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiRyneopQe78EMEIC0UXGAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 06:43:53
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 02:43:46.621137 2026] [security2:error] [pid 3291:tid 3291] [client 91.198.89.37:40612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.randymcelroy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.randymcelroy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiPBollUNV3_xNCuJj8AiAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-05 23:55:55
(5 days ago)
(wp_login_try) srv104 WP Login Attempt 91.198.89.37 (PL/Poland/www.manierait.pl): 10 in the last 360 ...
show more
(wp_login_try) srv104 WP Login Attempt 91.198.89.37 (PL/Poland/www.manierait.pl): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 22:09:26
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 18:09:18.392920 2026] [security2:error] [pid 28796:tid 28796] [client 91.198.89.37:40958] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.wild-goose.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.wild-goose.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aiNJDuTtInzSNF715tqupwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-05 20:42:13
(5 days ago)
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:48.0) Gecko/20100101 Firefox/48.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:43.0) Gecko/20100101 Firefox/43.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:22:42:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0"
[redacted] 91.198.89.37 - - [05/Jun/202
...
show less
Hacking
Web App Attack
Anonymous
2026-06-05 15:03:01
(6 days ago)
[redacted] 91.198.89.37 - - [05/Jun/2026:17:03:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mo ...
show more
[redacted] 91.198.89.37 - - [05/Jun/2026:17:03:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:17:03:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:17:03:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:82.0) Gecko/20100101 Firefox/82.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:17:03:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:46.0) Gecko/20100101 Firefox/46.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:17:03:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0"
[redacted] 91.198.89.37 - - [05/Jun/2026:17:03:00 +0200] "POST /xmlrpc.php
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 09:55:43
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.198.89.37 (www.manierait.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 05:55:39.804224 2026] [security2:error] [pid 18462:tid 18462] [client 91.198.89.37:42956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||altoshp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "altoshp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiKdG85fNHC5zWlf701QaQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack