๐ง๐ช
cmbplf
2026-08-02 01:31:30
(6 hours ago)
565 requests with url.path //xmlrpc.php
375 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
๐จ๐ณ
pengpeng
2026-07-27 18:34:54
(5 days ago)
monitor: on VM-0-7-ubuntu | port: 34672 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporte ...
show more
monitor: on VM-0-7-ubuntu | port: 34672 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ซ๐ท
sprmario
2025-09-11 22:02:02
(10 months ago)
Domain : muhammetmustafagunaltin.com
Rule : includephp
2025-08-13 10:11:39 192.168.1.68 GET /wp-incl ...
show more
Domain : muhammetmustafagunaltin.com
Rule : includephp
2025-08-13 10:11:39 192.168.1.68 GET /wp-includes/ID3/license.txt - 80 - 162.158.18.41 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 - muhammetmustafagunaltin.com 404 0 0 4921 613 451 - 130.195.241.22
show less
Port Scan
๐ฉ๐ช
grassau.com
2025-09-02 02:42:19
(11 months ago)
(wordpress) Failed wordpress login from 130.195.241.22 (UA/Ukraine/-)
Brute-Force
๐ธ๐ช
vaia.cloud
2025-09-02 01:38:02
(11 months ago)
trying wp-login.php/xmlrpc.php 65 times in 1 minutes
Brute-Force
Web App Attack
๐ฉ๐ช
dwmp
2025-09-02 01:01:48
(11 months ago)
WordPress login Brute-Force
Brute-Force
Web App Attack
๐ฉ๐ช
Mario Silber
2025-09-02 00:45:03
(11 months ago)
(wordpress) Failed wordpress login from 130.195.241.22 (UA/Ukraine/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-09-02 00:41:22
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 130.195.241.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.241.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 20:41:18.827180 2025] [security2:error] [pid 29393:tid 29393] [client 130.195.241.22:30863] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.versallis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.versallis.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aLY9LkxzCCiumzUNoRvqIwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-09-02 00:21:51
(11 months ago)
5.959 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-01 21:52:33
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 130.195.241.22 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.195.241.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 17:52:27.318952 2025] [security2:error] [pid 15803:tid 15803] [client 130.195.241.22:37982] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.uphillfarmvt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.uphillfarmvt.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aLYVmzpKRMsr1-IMy50PtAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-08-29 09:03:02
(11 months ago)
http-no-verb
Hacking
๐ซ๐ท
sprmario
2025-08-29 01:44:01
(11 months ago)
Domain : muhammetmustafagunaltin.com
Rule : env
2025-08-13 10:11:48 192.168.1.68 GET /blog/wp-includ ...
show more
Domain : muhammetmustafagunaltin.com
Rule : env
2025-08-13 10:11:48 192.168.1.68 GET /blog/wp-includes/wlwmanifest.xml - 80 - 162.158.18.41 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 - muhammetmustafagunaltin.com 404 0 0 4922 618 397 - 130.195.241.22
show less
Hacking
SQL Injection
๐ซ๐ท
sprmario
2025-08-28 07:02:05
(11 months ago)
Domain : muhammetmustafagunaltin.com
Rule : includephp
2025-08-13 10:11:39 192.168.1.68 GET /wp-incl ...
show more
Domain : muhammetmustafagunaltin.com
Rule : includephp
2025-08-13 10:11:39 192.168.1.68 GET /wp-includes/ID3/license.txt - 80 - 162.158.18.41 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 - muhammetmustafagunaltin.com 404 0 0 4921 613 451 - 130.195.241.22
show less
Port Scan
๐ซ๐ท
sprmario
2025-08-19 11:59:04
(11 months ago)
Domain : muhammetmustafagunaltin.com
Rule : xmlrpc
2025-08-13 10:11:45 192.168.1.68 GET /xmlrpc.php ...
show more
Domain : muhammetmustafagunaltin.com
Rule : xmlrpc
2025-08-13 10:11:45 192.168.1.68 GET /xmlrpc.php rsd 80 - 162.158.18.41 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 - muhammetmustafagunaltin.com 404 0 0 4918 600 395 - 130.195.241.22
show less
Web App Attack
๐ซ๐ท
sprmario
2025-08-19 10:16:04
(11 months ago)
Domain : muhammetmustafagunaltin.com
Rule : includephp
2025-08-13 10:11:39 192.168.1.68 GET /wp-incl ...
show more
Domain : muhammetmustafagunaltin.com
Rule : includephp
2025-08-13 10:11:39 192.168.1.68 GET /wp-includes/ID3/license.txt - 80 - 162.158.18.41 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 - muhammetmustafagunaltin.com 404 0 0 4921 613 451 - 130.195.241.22
show less
Port Scan