🇳🇴
jad-abuse
2026-08-30 08:24:55
(38 minutes ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
🇩🇪
Hazzard
2026-08-29 19:38:41
(13 hours ago)
(wordpress) Failed wordpress login from 103.209.18.115 (IN/India/-/-/-/[redacted]): (CF_ENABLE)
Brute-Force
Anonymous
2026-08-29 17:30:27
(15 hours ago)
103.209.18.115 - - [29/Aug/2026:17:30:26 +0000] "POST /xmlrpc.php HTTP/1.1" 404 35887 "-" "Mozilla/5 ...
show more
103.209.18.115 - - [29/Aug/2026:17:30:26 +0000] "POST /xmlrpc.php HTTP/1.1" 404 35887 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/13.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 09:52:03
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:51:55.780592 2026] [security2:error] [pid 1182356:tid 1182409] [client 103.209.18.115:51678] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rubenluis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rubenluis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorCuw7qgpa9LK24vMVJvwAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-23 08:45:05
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-08-22 15:22:38
(1 week ago)
(wordpress) Failed wordpress login from 103.209.18.115 (IN/India/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-08-22 05:30:29
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:30:25.194126 2026] [security2:error] [pid 7902:tid 7902] [client 103.209.18.115:55795] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||milliondollarbelt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "milliondollarbelt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aokz8VnB5oWqlYxNkrK6MwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 19:28:14
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 15:28:07.631448 2026] [security2:error] [pid 27626:tid 27626] [client 103.209.18.115:61625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||reallifelearninghub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "reallifelearninghub.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiCAR6TjUlaHny4R2xjZNgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-06-03 19:07:20
(2 months ago)
[WedJun0321:07:15.1998072026][security2:error][pid2185140:tid2185252][client103.209.18.115:0]ModSecu ...
show more
[WedJun0321:07:15.1998072026][security2:error][pid2185140:tid2185252][client103.209.18.115:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"pytag.ch\"][uri\"/xmlrpc.php\"][unique_id\"aiB7Y-8B7cFaZ1MrYaOldgAAAQo\"]
show less
Port Scan
Brute-Force
Web App Attack
🇩🇪
Martin Lundstrom
2026-06-03 13:50:51
(2 months ago)
https://www.eagleeye-intelligence.com — WordPress attack. Automatically detected and blocked.
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 12:23:05
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 08:22:59.329139 2026] [security2:error] [pid 28842:tid 28842] [client 103.209.18.115:64543] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||investorsfundingusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "investorsfundingusa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiAcoybTvqAD78zW0nbMMgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-06-03 07:40:50
(2 months ago)
Try to access /xmlrpc.php
Web App Attack
Anonymous
2026-06-03 03:56:54
(2 months ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=bridgesofpneumonology2026.com; logs=/var/log/httpd/domains/ ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=bridgesofpneumonology2026.com; logs=/var/log/httpd/domains/bridgesofpneumonology2026.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 02:47:38
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.209.18.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 22:47:34.554221 2026] [security2:error] [pid 6206:tid 6206] [client 103.209.18.115:63449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barecreationsaz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barecreationsaz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah-VxuYTJVArhb8WiZiPrgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 00:36:13
(2 months ago)
Attac
Brute-Force