๐ซ๐ท
masterguru
2026-07-24 06:24:35
(3 hours ago)
(xmlrpc) Apache: Failed xmlrpc access from 112.134.143.103 (LK/Sri Lanka/v4.dns.slt.lk): 10 in the l ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 112.134.143.103 (LK/Sri Lanka/v4.dns.slt.lk): 10 in the last 3600 secs (0-180)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-21 11:10:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:10:38.265783 2026] [security2:error] [pid 25279:tid 25279] [client 112.134.143.103:5447] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||idmadventures.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "idmadventures.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al9TruPWNWxNL8M20YO8awAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-07-21 11:07:50
(2 days ago)
Fail2Ban apache-tripwires
Web App Attack
Anonymous
2026-07-21 04:59:57
(3 days ago)
112.134.143.103 - - [21/Jul/2026:06:56:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Mozilla/5. ...
show more
112.134.143.103 - - [21/Jul/2026:06:56:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Mozilla/5.0 (Windows NT 6.2; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/85.0.0.0 Safari/537.36"
112.134.143.103 - - [21/Jul/2026:06:56:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT 6.2; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/85.0.0.0 Safari/537.36"
112.134.143.103 - - [21/Jul/2026:06:59:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/13.0.0.0 Safari/537.36"
112.134.143.103 - - [21/Jul/2026:06:59:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/13.0.0.0 Safari/537.36"
112.134.143.103 - - [21/Jul/2026:06:59:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Mozilla/5.0 (Windows NT 6.2; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/80.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-07-20 09:01:29
(4 days ago)
[MonJul2011:01:27.0166382026][security2:error][pid1445818:tid1445926][client112.134.143.103:0]ModSec ...
show more
[MonJul2011:01:27.0166382026][security2:error][pid1445818:tid1445926][client112.134.143.103:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"tcservices.ch\"][uri\"/xmlrpc.php\"][unique_id\"al3j539oyQcOJpsK-h65LgAAAFg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-07-17 11:42:15
(6 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 6.3; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/14.0.0.0 Safari/537.36
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:46:37
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:46:30.427356 2026] [security2:error] [pid 24920:tid 24920] [client 112.134.143.103:5809] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||southernstatespool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "southernstatespool.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aloIBrxEFXYTV9y2EQghyQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-07-14 10:12:49
(1 week ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 08:49:03
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 04:48:57.849830 2026] [security2:error] [pid 2460:tid 2460] [client 112.134.143.103:5813] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||enjoymycondos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "enjoymycondos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alCx-dFHB5Oyf2465nggmwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 07:35:09
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 03:35:04.437827 2026] [security2:error] [pid 2320:tid 2340] [client 112.134.143.103:5233] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chelseyrae.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chelseyrae.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alCgqJ6VkWy2MGbrfuTPNgAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-07-09 11:54:36
(2 weeks ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-08 10:19:14
(2 weeks ago)
Try to access /xmlrpc.php
Web App Attack
๐จ๐ญ
zynex
2026-07-08 09:56:28
(2 weeks ago)
URL Probing: /de/xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 11:37:09
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 112.134.143.103 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 07:37:04.595815 2026] [security2:error] [pid 22744:tid 22744] [client 112.134.143.103:5525] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arsenalfordemocracy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akZNYJ00B7cyeKqHn4sUJwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-02 08:07:55
(3 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 112.134.143.103 (LK/Sri Lanka/v4.dn ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 112.134.143.103 (LK/Sri Lanka/v4.dns.slt.lk): 1 in the last 3600 secs
show less
Web App Attack