๐ซ๐ฎ
KnightIndustries
2026-07-25 19:53:12
(1 day ago)
2026-07-25T21:52:50.531893+02:00 milkyway wordpress(oldscarborough.com)[624005]: XML-RPC authenticat ...
show more
2026-07-25T21:52:50.531893+02:00 milkyway wordpress(oldscarborough.com)[624005]: XML-RPC authentication failure for joshua from 112.207.209.42
2026-07-25T21:53:00.932159+02:00 milkyway wordpress(oldscarborough.com)[643455]: XML-RPC authentication failure for joshua from 112.207.209.42
2026-07-25T21:53:11.467680+02:00 milkyway wordpress(oldscarborough.com)[643456]: XML-RPC authentication failure for joshua from 112.207.209.42
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-25 19:23:47
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-25 18:55:17
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 14:55:11.421075 2026] [security2:error] [pid 1029235:tid 1029235] [client 112.207.209.42:54555] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.207.209.42 (+1 hits since last alert)|boaredraven.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "boaredraven.com"] [uri "/xmlrpc.php"] [unique_id "amUGj1ahYN4ePJMDyZBJYgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 11:31:18
(1 day ago)
(wordpress) Failed wordpress login from 112.207.209.42 (PH/Philippines/112.207.209.42.pldt.net)
Brute-Force
Anonymous
2026-07-25 10:22:02
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
yitzhaq
2026-07-25 09:53:17
(1 day ago)
112.207.209.42 - - [24/Jul/2026:16:46:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5089 "-" "Jetpack by ...
show more
112.207.209.42 - - [24/Jul/2026:16:46:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5089 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
112.207.209.42 - - [24/Jul/2026:16:46:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5089 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
112.207.209.42 - - [24/Jul/2026:16:46:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5088 "-" "Jetpack by WordPress.com"
112.207.209.42 - - [24/Jul/2026:16:46:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5090 "-" "Jetpack by WordPress.com"
112.207.209.42 - - [24/Jul/2026:16:47:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5090 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
112.207.209.42 - - [24/Jul/2026:16:47:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5089 "-" "Jetpack by WordPress.com"
112.207.209.42 - - [24/Jul/2026:16:47:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5089 "-" "Jetpack by WordPress.com"
112.207.209.42 - - [24/Jul/2026:16:47:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5089 "-" "WordPres
show less
Web App Attack
Brute-Force
Anonymous
2026-07-25 08:55:00
(1 day ago)
(wordpress) Failed wordpress login from 112.207.209.42 (PH/Philippines/112.207.209.42.pldt.net)
Brute-Force
๐ช๐ธ
alferez
2026-07-25 08:17:23
(1 day ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
Anonymous
2026-07-25 08:07:50
(1 day ago)
...
Web App Attack
๐ฉ๐ช
stinpriza
2026-07-25 06:29:09
(1 day ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 06:17:48
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 02:17:44.972790 2026] [security2:error] [pid 744501:tid 744501] [client 112.207.209.42:55776] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kontikimotorcycles.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kontikimotorcycles.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amRVCI2mpl2m4MGTA3KcPwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:06:10
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:06:05.384992 2026] [security2:error] [pid 2945689:tid 2945689] [client 112.207.209.42:56407] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.207.209.42 (+1 hits since last alert)|cycontechnology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cycontechnology.com"] [uri "/xmlrpc.php"] [unique_id "amO3naia1LwAiZN0GhOVVAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-24 18:12:34
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-24 17:08:43
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:08:37.684859 2026] [security2:error] [pid 3914403:tid 3914403] [client 112.207.209.42:56316] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thorndikestudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amOcFY5sDO-5GPQ-h1kIMAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:25:29
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 112.207.209.42 (112.207.209.42.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:25:21.242318 2026] [security2:error] [pid 3994560:tid 3994560] [client 112.207.209.42:54984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||takemehomedogrescue.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "takemehomedogrescue.org"] [uri "/wp-json/wp/v2/users"] [unique_id "amOR8Z4w-s77SOKoO7bNugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack