๐บ๐ธ
TPI-Abuse
2026-07-02 01:27:20
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 103.173.244.249 (249.244.173.103.jnpl.jeebr.net ...
show more
(mod_security) mod_security (id:225170) triggered by 103.173.244.249 (249.244.173.103.jnpl.jeebr.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 21:27:09.439860 2026] [security2:error] [pid 15460:tid 15460] [client 103.173.244.249:50676] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dandksupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dandksupply.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akW-bRKHY6hhc4zU_gpjygAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-02 01:20:45
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
249.244.173.103.jnpl.jeebr.net
Web App Attack
๐จ๐ญ
4server
2026-07-01 20:45:49
(1 day ago)
[WedJul0122:45:45.1248502026][security2:error][pid1407583:tid1407819][client103.173.244.249:0]ModSec ...
show more
[WedJul0122:45:45.1248502026][security2:error][pid1407583:tid1407819][client103.173.244.249:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"aidweb.ch\"][uri\"/xmlrpc.php\"][unique_id\"akV8eV3ZX85G6fnv14ZCdgAAAIE\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 14:33:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 103.173.244.249 (249.244.173.103.jnpl.jeebr.net ...
show more
(mod_security) mod_security (id:225170) triggered by 103.173.244.249 (249.244.173.103.jnpl.jeebr.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 10:33:46.741574 2026] [security2:error] [pid 4314:tid 4314] [client 103.173.244.249:54263] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prostar.industries"] [uri "/wp-json/wp/v2/users"] [unique_id "akUlSiT_Gxrgq7Z2L6WswQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-07-01 14:10:22
(1 day ago)
Wordpress Vunerability attack
Web App Attack
๐ณ๐ด
jad-abuse
2026-06-26 08:29:24
(6 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 08:25:17
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 103.173.244.249 (249.244.173.103.jnpl.jeebr.net ...
show more
(mod_security) mod_security (id:225170) triggered by 103.173.244.249 (249.244.173.103.jnpl.jeebr.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 04:25:12.915213 2026] [security2:error] [pid 14315:tid 14315] [client 103.173.244.249:62372] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dynamic-therapy-mn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dynamic-therapy-mn.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aj43aL3QlD-JZo6NMrcCcQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-06-26 06:22:19
(6 days ago)
Web vulnerability probing: /xmlrpc.php
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-26 04:56:56
(1 week ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-06-24 21:14:49
(1 week ago)
[WedJun2423:14:46.0890642026][security2:error][pid354748:tid354846][client103.173.244.249:0]ModSecur ...
show more
[WedJun2423:14:46.0890642026][security2:error][pid354748:tid354846][client103.173.244.249:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"ilcartiglio.ch\"][uri\"/xmlrpc.php\"][unique_id\"ajxIxm7jBcs52Jl9ZHexfwAAAJY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-06-23 18:34:30
(1 week ago)
-:443 103.173.244.249 - - [23/Jun/2026:20:34:29 +0200] - "POST /xmlrpc.php HTTP/1.1" 404 5939 "-" "M ...
show more
-:443 103.173.244.249 - - [23/Jun/2026:20:34:29 +0200] - "POST /xmlrpc.php HTTP/1.1" 404 5939 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/13.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐ง๐ช
voormedia
2026-06-23 18:28:24
(1 week ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-06-23 18:01:47
(1 week ago)
CMS/framework probe: 103.173.244.249 - - [23/Jun/2026:20:01:46 +0200] "POST /xmlrpc.php HTTP/1.1" 40 ...
show more
CMS/framework probe: 103.173.244.249 - - [23/Jun/2026:20:01:46 +0200] "POST /xmlrpc.php HTTP/1.1" 404 162 "-" "Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Opera/74.0.0.0 Safari/537.36" asn=138296 org="Juweriyah Networks Private Limited" country=IN
...
show less
Web App Attack
๐ฉ๐ช
Hazzard
2026-06-21 13:49:14
(1 week ago)
(wordpress) Failed wordpress login from 103.173.244.249 (IN/India/-/-/249.244.173.103.jnpl.jeebr.net ...
show more
(wordpress) Failed wordpress login from 103.173.244.249 (IN/India/-/-/249.244.173.103.jnpl.jeebr.net/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-21 03:54:25
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.173.244.249 (249.244.173.103.jnpl.jeebr.net ...
show more
(mod_security) mod_security (id:225170) triggered by 103.173.244.249 (249.244.173.103.jnpl.jeebr.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 23:54:21.739989 2026] [security2:error] [pid 27183:tid 27183] [client 103.173.244.249:61978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||agrollum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "agrollum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajdgbTHvYGyF70eZdRDmPAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack