Anonymous
2026-07-29 07:00:00
(3 hours ago)
Automated Apache web application probing in selected 24h window; attempts=247, unique_paths=1, error ...
show more
Automated Apache web application probing in selected 24h window; attempts=247, unique_paths=1, error_responses=240; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 hours ago)
Apache probe; attempts=348; exact paths: /xmlrpc.php
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-07-29 05:40:06
(4 hours ago)
2026-07-29 07:35:42 WordPress login error from 132.251.2.124: invalid_username && 2026-07-29 07:35:5 ...
show more
2026-07-29 07:35:42 WordPress login error from 132.251.2.124: invalid_username && 2026-07-29 07:35:52 WordPress login error from 132.251.2.124: invalid_username && 2026-07-29 07:36:02 WordPress login error from 132.251.2.124: invalid_username && 22 more within 20 minutes
show less
Brute-Force
๐ณ๐ฑ
Site.eu
2026-07-29 05:38:30
(4 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
YF
2026-07-29 04:00:13
(6 hours ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐ณ๐ฑ
debestelapp
2026-07-28 21:00:05
(13 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 06:15:38
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 132.251.2.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 132.251.2.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 02:15:31.148693 2026] [security2:error] [pid 3482904:tid 3482940] [client 132.251.2.124:19886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 132.251.2.124 (+1 hits since last alert)|giere.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "giere.us"] [uri "/xmlrpc.php"] [unique_id "amhJA20Dp1DVUgj55AIMGAAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 04:14:09
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 132.251.2.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 132.251.2.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 00:14:05.711364 2026] [security2:error] [pid 1540393:tid 1540393] [client 132.251.2.124:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 132.251.2.124 (+1 hits since last alert)|area52designs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "area52designs.com"] [uri "/xmlrpc.php"] [unique_id "amgsjZraa86CTpdpOWD8SAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-28 02:08:01
(1 day ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,ice02]
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-28 01:07:01
(1 day ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [mx02,wa02]
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 22:54:32
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 132.251.2.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 132.251.2.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:54:24.850268 2026] [security2:error] [pid 2240352:tid 2240352] [client 132.251.2.124:52534] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 132.251.2.124 (+1 hits since last alert)|natickvillagerentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "natickvillagerentals.com"] [uri "/xmlrpc.php"] [unique_id "amfhoFn6KZVUnJEb3m9sfwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-27 22:52:30
(1 day ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: WordPress.com; https:// ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: WordPress.com; https://wordpress.com
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-27 22:21:35
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-27 22:05:03
(1 day ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [wa01]
Bad Web Bot
Web App Attack
๐บ๐ธ
bigwavedave
2026-07-27 19:36:39
(1 day ago)
Wordpress Attack
Web App Attack