π¬π§
gigatech
2026-07-29 19:20:03
(14 hours ago)
Webserver Probing
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=23; exact paths: /xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 19:14:05
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 120.29.78.35 (35.78.29.120-rev.convergeict.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 120.29.78.35 (35.78.29.120-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 15:13:56.637970 2026] [security2:error] [pid 448552:tid 448595] [client 120.29.78.35:26720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grupojdg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grupojdg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amj_dL0TqOzUQup8supfSgAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Penny Packer
2026-07-27 14:28:03
(2 days ago)
Fail2Ban apache-tripwires
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 14:24:47
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 120.29.78.35 (35.78.29.120-rev.convergeict.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 120.29.78.35 (35.78.29.120-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:24:41.812779 2026] [security2:error] [pid 172844:tid 172844] [client 120.29.78.35:16159] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lasertherapyoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lasertherapyoc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amdqKeHI04Va4KMIKP3CawAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 14:14:58
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π«π·
ELYAZ
2026-07-24 18:39:24
(5 days ago)
(wordpress) Failed wordpress login from 120.29.78.35 (PH/Philippines/35.78.29.120-rev.convergeict.co ...
show more
(wordpress) Failed wordpress login from 120.29.78.35 (PH/Philippines/35.78.29.120-rev.convergeict.com): (CF_ENABLE)
show less
Brute-Force
π©πͺ
big-cloud.nl
2026-07-24 16:07:06
(5 days ago)
Try to access /xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 15:25:10
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 120.29.78.35 (35.78.29.120-rev.convergeict.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 120.29.78.35 (35.78.29.120-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 11:25:02.889526 2026] [security2:error] [pid 10956:tid 10956] [client 120.29.78.35:44072] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hendersonhomes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hendersonhomes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alzsToBS3OxU6Yjp8S-htgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Tha_14
2026-07-19 09:19:03
(1 week ago)
Limit on login attempts is reached
Brute-Force
π¬π·
setupgr
2026-07-19 09:15:46
(1 week ago)
(XMLRPC) WP XMLRPC Attack 120.29.78.35 (PH/Philippines/Central Luzon/San Isidro/-/[AS17639 CONVERGE- ...
show more
(XMLRPC) WP XMLRPC Attack 120.29.78.35 (PH/Philippines/Central Luzon/San Isidro/-/[AS17639 CONVERGE-AS Converge ICT Solutions Inc.]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 120.29.78.35 - - [19/Jul/2026:12:11:22 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18936 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36"
show less
Port Scan
π«π·
SpaceHost-Server
2026-07-18 22:26:07
(1 week ago)
Brute-Force
Web App Attack
π©πͺ
joharikop
2026-07-18 19:21:11
(1 week ago)
Nginx: WordPress/CMS probe (wp-admin, wp-login, xmlrpc). Automated ban via fail2ban nginx-cms-probes ...
show more
Nginx: WordPress/CMS probe (wp-admin, wp-login, xmlrpc). Automated ban via fail2ban nginx-cms-probes jail.
show less
Web App Attack
Anonymous
2026-07-18 12:49:12
(1 week ago)
120.29.78.35 - - [18/Jul/2026:14:46:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Mozilla/5.0 ( ...
show more
120.29.78.35 - - [18/Jul/2026:14:46:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/61.0.0.0 Safari/537.36"
120.29.78.35 - - [18/Jul/2026:14:46:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/61.0.0.0 Safari/537.36"
120.29.78.35 - - [18/Jul/2026:14:48:34 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Mozilla/5.0 (Linux; Android 10; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.0.0 Safari/537.36"
120.29.78.35 - - [18/Jul/2026:14:48:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Linux; Android 10; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.0.0 Safari/537.36"
120.29.78.35 - - [18/Jul/2026:14:49:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/68.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-18 07:09:35
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 120.29.78.35 (35.78.29.120-rev.convergeict.com) ...
show more
(mod_security) mod_security (id:225170) triggered by 120.29.78.35 (35.78.29.120-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 03:09:26.859822 2026] [security2:error] [pid 18772:tid 18772] [client 120.29.78.35:26700] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ultratecnologia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ultratecnologia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alsmpucvq4Zk-Q3pGxE7hAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack