🇩🇪
LRob
2026-08-03 13:41:00
(1 month ago)
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_forma ...
show more
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/cat_ids~661,148,190,122/tag_ids~333,593,241,469,539/request_format~json/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
show less
DDoS Attack
Web App Attack
🇫🇷
bigorre.org
2026-07-18 10:55:05
(1 month ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
🇩🇪
Tha_14
2026-07-13 10:31:40
(2 months ago)
Limit on login attempts is reached
Brute-Force
🇺🇸
TPI-Abuse
2026-07-13 06:05:55
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.126.36.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.126.36.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 02:05:51.283369 2026] [security2:error] [pid 25225:tid 25225] [client 103.126.36.6:12993] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kadinisi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kadinisi.org"] [uri "/wp-json/wp/v2/users"] [unique_id "alSAP4PamV66r68tbmKgrwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-07-13 04:25:37
(2 months ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
omc
2026-07-12 11:25:29
(2 months ago)
POST /xmlrpc.php [Q4].
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-12 09:49:26
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.126.36.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.126.36.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 05:49:19.092807 2026] [security2:error] [pid 4378:tid 4390] [client 103.126.36.6:7780] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||munatseng.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "munatseng.org"] [uri "/wp-json/wp/v2/users"] [unique_id "alNjHy4L9jTIt6K9myySzwAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
apislytics
2026-07-11 08:53:40
(2 months ago)
Automatic hard ban after repeated rate-limit abuse
Brute-Force
🇳🇱
Site.eu
2026-07-11 04:28:53
(2 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇺🇸
lostswordfish.com
2026-07-08 11:02:04
(2 months ago)
Wordfence waf block on parsol
Web App Attack
🇲🇹
Malta
2026-07-07 04:27:20
(2 months ago)
103.126.36.6 - - [07/Jul/2026:06:27:19 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; I ...
show more
103.126.36.6 - - [07/Jul/2026:06:27:19 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/91.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇺🇸
kosada.com
2026-07-06 21:31:02
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇳🇱
Site.eu
2026-07-06 10:32:43
(2 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇸🇪
vaia.cloud
2026-07-04 09:22:01
(2 months ago)
trying wp-login.php/xmlrpc.php 30 times in 1 minutes
Brute-Force
Web App Attack
🇫🇷
Hippoline
2026-07-04 09:01:50
(2 months ago)
[Sat Jul 04 10:59:11.512925 2026] [authz_core:error] [pid 23357] [client 103.126.36.6:7101] AH01630: ...
show more
[Sat Jul 04 10:59:11.512925 2026] [authz_core:error] [pid 23357] [client 103.126.36.6:7101] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
[Sat Jul 04 10:59:14.570925 2026] [authz_core:error] [pid 25873] [client 103.126.36.6:7143] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
[Sat Jul 04 11:01:42.324101 2026] [authz_core:error] [pid 31489] [client 103.126.36.6:8771] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
[Sat Jul 04 11:01:42.327614 2026] [authz_core:error] [pid 20193] [client 103.126.36.6:8770] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
[Sat Jul 04 11:01:49.712305 2026] [authz_core:error] [pid 30636] [client 103.126.36.6:8852] AH01630: client denied by server configuration: /var/www/clients/client3/web4/web/xmlrpc.php
...
show less
Brute-Force
Web App Attack