๐ณ๐ด
jad-abuse
2026-07-29 16:37:52
(20 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-07-07 15:26:39
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-05 06:20:13
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 02:20:08.750381 2026] [security2:error] [pid 28661:tid 28661] [client 103.105.86.60:56566] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gasoilliquidsdaily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gasoilliquidsdaily.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akn3mOpYot-zdyuIzA2MBgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-05 05:52:15
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
consul.to
2026-07-01 19:03:20
(4 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ท๐ด
INTEQ
2026-07-01 11:11:45
(4 weeks ago)
Web attack from 103.105.86.60
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 07:23:05
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 03:22:57.914258 2026] [security2:error] [pid 12288:tid 12288] [client 103.105.86.60:62218] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||verdeprofundo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "verdeprofundo.net"] [uri "/wp-json/wp/v2/users"] [unique_id "akIdUQJqkpb3U5T6AKQSJwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-20 09:15:26
(1 month ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 05:15:50
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 01:15:45.774985 2026] [security2:error] [pid 11359:tid 11359] [client 103.105.86.60:56422] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oliverhardy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oliverhardy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajDcAbqcZZX7d-sGiiT3MAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 10:17:27
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 06:17:22.664622 2026] [security2:error] [pid 23307:tid 23419] [client 103.105.86.60:64934] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rawhabitat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rawhabitat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai_RMpiYjAVNxpaCIQn6DAAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
YF
2026-05-25 09:15:18
(2 months ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-25 08:58:34
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 04:58:27.100729 2026] [security2:error] [pid 4111:tid 4111] [client 103.105.86.60:56793] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||loriarsenault.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "loriarsenault.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahQPM8xuXNU--oGbiLJ_dgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-16 06:14:20
(2 months ago)
[SatMay1608:14:13.6813022026][security2:error][pid779777:tid780108][client103.105.86.60:0]ModSecurit ...
show more
[SatMay1608:14:13.6813022026][security2:error][pid779777:tid780108][client103.105.86.60:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"giuristifriburgo.ch\"][uri\"/xmlrpc.php\"][unique_id\"aggLNVnTY3adgs8wjE-fkwAAAI4\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 16:25:22
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 103.105.86.60 (103.105.86.60.earth.net.bd): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 12:25:17.713686 2026] [security2:error] [pid 20550:tid 20550] [client 103.105.86.60:59436] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tell-me-first.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tell-me-first.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afTT7Ryj_fS-dLExnWVHNAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-05-01 10:48:39
(2 months ago)
103.105.86.60 - - [01/May/2026:04:48:38 -0600] "POST /xmlrpc.php HTTP/1.1" 302 138 "-" "Mozilla/5.0 ...
show more
103.105.86.60 - - [01/May/2026:04:48:38 -0600] "POST /xmlrpc.php HTTP/1.1" 302 138 "-" "Mozilla/5.0 (Windows NT 10.0; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.0.0 Safari/537.36"
...
show less
Web App Attack