๐ฉ๐ช
LRob
2026-09-24 16:30:07
(1 week ago)
This address sends abusive requests to WordPress sites we host: user enumeration through the REST AP ...
show more
This address sends abusive requests to WordPress sites we host: user enumeration through the REST API, xmlrpc.php calls the site refuses, endpoints the site does not serve. These are the reconnaissance and attack calls of automated WordPress attack tools, blocked on sight. Please check the machine behind it. | method: POST | path: /xmlrpc.php | 2026-09-24 16:30 UTC
show less
Web App Attack
Hacking
๐ช๐ธ
librebit
2026-09-21 20:32:28
(1 week ago)
Brute force
Brute-Force
Anonymous
2026-09-21 16:56:11
(1 week ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-18 14:33:47
(2 weeks ago)
Brute-force login attack detected by WordPress firewall.
Brute-Force
Web App Attack
Anonymous
2026-08-24 16:45:35
(1 month ago)
Web attack blocked by Wordfence on mezzia.nl (4 hits). Reported by CRMON.
Web App Attack
๐ช๐ธ
librebit
2026-07-09 10:04:41
(2 months ago)
Brute force
Brute-Force
๐ฉ๐ช
Vegascosmetics
2026-07-04 17:06:29
(3 months ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐ฉ๐ช
HandyTreff.de
2026-06-29 23:04:23
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -32.234 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -32.234 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Sa
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-15 14:18:56
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.113.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.113.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 10:18:51.101198 2026] [security2:error] [pid 21659:tid 21659] [client 130.49.113.228:25491] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abundancecompany.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abundancecompany.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajAJy8RJCUFLecwlx5QLCQAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 06:53:23
(3 months ago)
(caddyscan) Scanner path probe from 130.49.113.228 (DE/Germany/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 130.49.113.228 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 130.49.113.228 - - [09/Jun/2026:06:53:14 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 130.49.113.228 - - [09/Jun/2026:06:53:16 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 130.49.113.228 - - [09/Jun/2026:06:53:17 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 130.49.113.228 - - [09/Jun/2026:06:53:21 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 130.49.113.228 - - [09/Jun/2026:06:53:22 +0000] "GET /wp-login.php HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-21 21:43:02
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.113.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.113.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 17:42:54.764676 2026] [security2:error] [pid 31269:tid 31269] [client 130.49.113.228:12277] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||n-vil.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "n-vil.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag98XrWy5pX3M71R82EodAAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2026-05-20 04:07:27
(4 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 00:05:58
(4 months ago)
(mod_security) mod_security (id:218580) triggered by 130.49.113.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 130.49.113.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 20:05:53.448771 2026] [security2:error] [pid 15121:tid 15121] [client 130.49.113.228:29503] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:lang. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||www.genesis-castle.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "www.genesis-castle.com"] [uri "/gallery/index.php"] [unique_id "age04UmBVN-V7vefAIEYhAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-05-13 04:47:46
(4 months ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-09 16:24:30
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.113.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.113.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 12:24:26.353062 2026] [security2:error] [pid 1531:tid 1531] [client 130.49.113.228:41345] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geceindia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geceindia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "af9fugT2Pvy6GNNqAo-XdAAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack