π©πͺ
bsoft.de
2026-08-23 01:33:05
(1 day ago)
130.195.240.3 - - [23/Aug/2026:03:33:00 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 200 804 "-" "Mozilla/ ...
show more
130.195.240.3 - - [23/Aug/2026:03:33:00 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 200 804 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
130.195.240.3 - - [23/Aug/2026:03:33:02 +0200] "GET //wp-json/wp/v2/users/ HTTP/1.1" 404 148 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
130.195.240.3 - - [23/Aug/2026:03:33:04 +0200] "POST //xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Web App Attack
π¦πΉ
penguin-solutions.at
2026-08-23 00:03:12
(1 day ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
π¬π§
Apache
2026-08-22 16:21:08
(1 day ago)
(mod_security) mod_security (id:210410) triggered by 130.195.240.3 (MD/Moldova/-): 5 in the last 300 ...
show more
(mod_security) mod_security (id:210410) triggered by 130.195.240.3 (MD/Moldova/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
π§πͺ
cmbplf
2026-08-22 14:45:18
(1 day ago)
419 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-22 13:45:15
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:45:07.869354 2026] [security2:error] [pid 7781:tid 7781] [client 130.195.240.3:46879] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daisydoesoap.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daisydoesoap.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aomn4y6iQbAGYbXnWx65qQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
wlt-blocker
2026-08-22 12:04:05
(1 day ago)
Unauthorized access to webpage admin
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 11:34:12
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 07:34:05.136521 2026] [security2:error] [pid 5331:tid 5331] [client 130.195.240.3:1721] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daebakdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daebakdesign.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aomJLfWZcro0FjDDKCl0mgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 10:23:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:23:05.608500 2026] [security2:error] [pid 9062:tid 9062] [client 130.195.240.3:64387] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.d-sinema.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aol4ictIy6SFEcolLG93GAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 09:35:28
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:35:24.218785 2026] [security2:error] [pid 31450:tid 31478] [client 130.195.240.3:38646] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosureinternetservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosureinternetservices.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoltXHreuRvbScIPyUijfQAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
cwytech
2026-08-22 08:23:09
(1 day ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/wordpress-xmlrpc-bf-high.
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-22 07:00:23
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-08-22 05:35:15
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π«π·
dynamix
2026-08-22 05:25:41
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 04:57:15
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.240.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 00:57:08.924561 2026] [security2:error] [pid 28302:tid 28302] [client 130.195.240.3:2203] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cubbylure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cubbylure.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoksJDXlA0UarddbEpY7fAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
electronico
2026-08-22 04:41:03
(1 day ago)
130.195.240.3 - - [22/Aug/2026:15:41:03 +1100] "GET //xmlrpc.php?rsd HTTP/1.1" 200 1020 "-" "Mozilla ...
show more
130.195.240.3 - - [22/Aug/2026:15:41:03 +1100] "GET //xmlrpc.php?rsd HTTP/1.1" 200 1020 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Brute-Force
Web App Attack