๐ซ๐ท
dynamix
2026-06-11 01:28:50
(18 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
rsiddall
2026-06-10 05:49:56
(1 day ago)
115.79.136.140 - - [10/Jun/2026:01:49:55 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5. ...
show more
115.79.136.140 - - [10/Jun/2026:01:49:55 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:59.0) Gecko/20100101 Firefox/59.0"
115.79.136.140 - - [10/Jun/2026:01:49:55 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 16:54:19
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:54:11.011775 2026] [security2:error] [pid 19661:tid 19661] [client 115.79.136.140:37971] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ismaelcavazos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ismaelcavazos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aibzs1nNQOdzdye9ztwVRgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 12:48:12
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 08:48:04.049819 2026] [security2:error] [pid 2597:tid 2597] [client 115.79.136.140:43699] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.michelehoop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aia6BI7-n7OAHVw-YBiONQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 09:26:44
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 05:26:39.649482 2026] [security2:error] [pid 15860:tid 15860] [client 115.79.136.140:58673] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.wild-goose.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.wild-goose.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aiaKz2Q_y_AVaMBRXw9vBAAAAH4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-08 01:00:04
(3 days ago)
Exploited Host
๐ณ๐ฑ
Mangelot Hosting
2026-06-07 23:38:30
(3 days ago)
(wp_login_try) srv101 WP Login Attempt 115.79.136.140 (VN/Vietnam/-): 10 in the last 3600 secs; Port ...
show more
(wp_login_try) srv101 WP Login Attempt 115.79.136.140 (VN/Vietnam/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 08:34:06
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 04:34:00.822914 2026] [security2:error] [pid 8243:tid 8243] [client 115.79.136.140:52645] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soundtrax.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aiUs-MGwpLVzU62gAohtTwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-06 15:10:30
(5 days ago)
[redacted] 115.79.136.140 - - [06/Jun/2026:17:10:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" " ...
show more
[redacted] 115.79.136.140 - - [06/Jun/2026:17:10:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0"
[redacted] 115.79.136.140 - - [06/Jun/2026:17:10:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0"
[redacted] 115.79.136.140 - - [06/Jun/2026:17:10:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:42.0) Gecko/20100101 Firefox/42.0"
[redacted] 115.79.136.140 - - [06/Jun/2026:17:10:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:98.0) Gecko/20100101 Firefox/98.0"
[redacted] 115.79.136.140 - - [06/Jun/2026:17:10:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0"
[redacted] 115.79.136.140 - - [06/Jun/2026:17:10:29 +0200] "POST /xmlrpc.php HTTP/1.1" 20
...
show less
Hacking
Web App Attack
๐ซ๐ท
tecnicorioja
2026-06-05 22:00:05
(5 days ago)
POST /xmlrpc.php [05/Jun/2026:04:35:27
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 20:20:10
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 16:20:05.425918 2026] [security2:error] [pid 7464:tid 7464] [client 115.79.136.140:53893] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ironsightsarmory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ironsightsarmory.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiMvdZyAK7ekaCsoOB4aVwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-06-05 15:48:12
(6 days ago)
115.79.136.140 - - [05/Jun/2026:17:48:09 +0200] "POST /wp-login.php HTTP/1.1" 200 3515 "-" "Mozilla/ ...
show more
115.79.136.140 - - [05/Jun/2026:17:48:09 +0200] "POST /wp-login.php HTTP/1.1" 200 3515 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"
115.79.136.140 - - [05/Jun/2026:17:48:10 +0200] "POST /wp-login.php HTTP/1.1" 200 3516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0"
115.79.136.140 - - [05/Jun/2026:17:48:10 +0200] "POST /wp-login.php HTTP/1.1" 200 3556 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0"
115.79.136.140 - - [05/Jun/2026:17:48:11 +0200] "POST /wp-login.php HTTP/1.1" 200 3516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0"
115.79.136.140 - - [05/Jun/2026:17:48:12 +0200] "POST /wp-login.php HTTP/1.1" 200 3516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 13:49:46
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 09:49:36.880295 2026] [security2:error] [pid 8687:tid 8687] [client 115.79.136.140:53561] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.smoothiessoupssalads.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.smoothiessoupssalads.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiGCcBYEuMXeXgtvZG_guQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-04 12:20:09
(1 week ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 10:15:52
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 115.79.136.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 06:15:47.728362 2026] [security2:error] [pid 7940:tid 7940] [client 115.79.136.140:45823] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.zerotaxlab.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.zerotaxlab.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiFQU5H23IaHTO4G7U1FRQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack