Anonymous
2026-06-24 05:04:02
(5 days ago)
<jail> banned by fail2ban
Brute-Force
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-06-24 02:09:12
(5 days ago)
Blocked by YFC Security on https://fencingforward.com โ type: xmlrpc_attempts
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-06-24 02:05:32
(5 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 13.83.167.48 (US/United States/-): 3 in the la ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 13.83.167.48 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/06/24 03:16:48 [error] 325606#325606: *369517 access forbidden by rule, client: 13.83.167.48, server: dsedivisedalavoro.it, request: "POST /xmlrpc.php HTTP/1.1", host: "dsedivisedalavoro.it"
13.83.167.48 - - [24/Jun/2026:03:22:32 +0200] "GET /wp-json/wp/v2/users/ HTTP/2.0" 404 201 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 OPR/109.0.0.0" "13.83.167.48" host=conapipescara.it
13.83.167.48 - - [24/Jun/2026:04:05:29 +0200] "GET /wp-json/wp/v2/users/ HTTP/1.1" 200 1617 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 OPR/110.0.0.0" "-" host=parolestrategiche.it
show less
Port Scan
๐ธ๐ช
vaia.cloud
2026-06-24 02:04:03
(5 days ago)
trying wp-login.php/xmlrpc.php 30 times in 1 minutes
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-24 02:02:17
(5 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-06-24 01:56:55
(5 days ago)
[ns31.kdns.gr] httpd-xmlrpc-post: sites=dimitrisanousis.com; logs=/var/log/httpd/domains/dimitrisano ...
show more
[ns31.kdns.gr] httpd-xmlrpc-post: sites=dimitrisanousis.com; logs=/var/log/httpd/domains/dimitrisanousis.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 01:52:04
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 13.83.167.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 13.83.167.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 21:51:59.352321 2026] [security2:error] [pid 22142:tid 22142] [client 13.83.167.48:60420] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frickandfracks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frickandfracks.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajs4P69bMlHR9wQLT2fLXQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-24 01:19:33
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 01:18:27
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 13.83.167.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 13.83.167.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 21:18:20.738668 2026] [security2:error] [pid 3165:tid 3165] [client 13.83.167.48:62195] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goldencalculator.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goldencalculator.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajswXMA_MZLES48B8dN6PwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 01:18:00
(5 days ago)
13.83.167.48 - - [24/Jun/2026:01:17:58 +0000] "GET /wp-json/wp/v2/users/ HTTP/1.1" 404 49903 "-" "Mo ...
show more
13.83.167.48 - - [24/Jun/2026:01:17:58 +0000] "GET /wp-json/wp/v2/users/ HTTP/1.1" 404 49903 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-06-24 01:00:52
(5 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-xmlrpc-bf-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 00:45:11
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 13.83.167.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 13.83.167.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 20:45:05.125253 2026] [security2:error] [pid 12330:tid 12330] [client 13.83.167.48:62049] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vrbsroma.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vrbsroma.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajsokdBebaUmzQtJGpJvbwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-24 00:32:54
(5 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 00:21:47
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 13.83.167.48 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 13.83.167.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 20:21:40.562691 2026] [security2:error] [pid 12842:tid 12842] [client 13.83.167.48:60730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||davefortier.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "davefortier.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajsjFOQ_35ztPe19_Mg7fQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-06-24 00:21:44
(5 days ago)
trolling for resource vulnerabilities
Web App Attack