๐จ๐ญ
4server
2026-07-24 17:16:56
(6 hours ago)
[FriJul2419:16:52.3666692026][security2:error][pid86666:tid86941][client103.133.175.97:0]ModSecurity ...
show more
[FriJul2419:16:52.3666692026][security2:error][pid86666:tid86941][client103.133.175.97:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"urbani.ch\"][uri\"/xmlrpc.php\"][unique_id\"amOeBL6xPiHkhew5vb4AJQAAAIQ\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-20 18:12:44
(4 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-20 09:54:43
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 05:54:38.264184 2026] [security2:error] [pid 18329:tid 18329] [client 103.133.175.97:55480] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||verdeprofundo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "verdeprofundo.net"] [uri "/wp-json/wp/v2/users"] [unique_id "al3wXv6u7E0pzjdiS8TibgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-18 16:41:38
(6 days ago)
Try to access /xmlrpc.php
Web App Attack
๐ซ๐ท
ELYAZ
2026-07-18 12:51:21
(6 days ago)
(wordpress) Failed wordpress login from 103.133.175.97 (BD/Bangladesh/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-14 07:18:02
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 03:17:55.084232 2026] [security2:error] [pid 4980:tid 4983] [client 103.133.175.97:53985] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rubenluis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rubenluis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alXiowt1HhBdxFIkksUAcwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-09 17:48:53
(2 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-07-08 08:23:27
(2 weeks ago)
Unauthorized access to webpage admin
Web App Attack
๐ฉ๐ช
abuse-detection
2026-07-07 16:15:09
(2 weeks ago)
Web security detection (http-wordpress-auth-probes); path=/xmlrpc.php; status=404
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-07-07 06:47:44
(2 weeks ago)
(xmlrpc) Failed xmlrpc access from 103.133.175.97 (BD/Bangladesh/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-05 10:19:25
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 06:19:21.921333 2026] [security2:error] [pid 6016:tid 6016] [client 103.133.175.97:61616] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lumentravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lumentravel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akovqecLPLT1e5xLMlT8UAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 13:27:03
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 09:26:55.366721 2026] [security2:error] [pid 5201:tid 5201] [client 103.133.175.97:57856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nordicbuilders.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nordicbuilders.net"] [uri "/wp-json/wp/v2/users"] [unique_id "akkKHwvlsie_yfOZw5HwKwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-04 12:11:56
(2 weeks ago)
[SatJul0414:11:54.0751732026][security2:error][pid1475187:tid1475207][client103.133.175.97:0]ModSecu ...
show more
[SatJul0414:11:54.0751732026][security2:error][pid1475187:tid1475207][client103.133.175.97:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"mgevents.ch\"][uri\"/xmlrpc.php\"][unique_id\"akj4inL1eolwFiDFaLaiwgAAAAg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-04 10:55:41
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 18:46:37
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.133.175.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 14:46:34.328526 2026] [security2:error] [pid 25342:tid 25342] [client 103.133.175.97:62945] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lysedzija.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akayCqAS_rz5WlKw9x2gJgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack