๐ช๐ธ
Gem
2026-06-26 22:14:47
(13 hours ago)
Unauthorized web scan.
Web App Attack
๐ต๐ฑ
Wepted
2026-06-26 03:07:41
(1 day ago)
Port scan detected by honeypot
Port Scan
Hacking
๐ฆ๐น
neo72
2026-06-24 15:10:15
(2 days ago)
Detected malicious activity - bulk block
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-24 14:34:03
(2 days ago)
Wordfence waf block on robdarnell
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 14:03:46
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 135.119.86.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 135.119.86.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 10:03:40.606311 2026] [security2:error] [pid 25991:tid 25991] [client 135.119.86.96:1587] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puckerbottombikinis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puckerbottombikinis.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajvjvEUYSCxFb6MHzC64swAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-06-24 13:54:45
(2 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-24 13:50:31
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-24 13:47:36
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐ง๐ช
cmbplf
2026-06-24 13:36:10
(2 days ago)
9.797 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-24 13:35:44
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 135.119.86.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 135.119.86.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 09:35:37.729293 2026] [security2:error] [pid 17338:tid 17338] [client 135.119.86.96:2413] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fruitinthedesert.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fruitinthedesert.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajvdKaMtOe86C0P3gKeSrwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-06-24 13:32:32
(2 days ago)
135.119.86.96 - - [24/Jun/2026:21:32:32 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6586 "-" "Mozilla/5.0 ...
show more
135.119.86.96 - - [24/Jun/2026:21:32:32 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6586 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
135.119.86.96 - - [24/Jun/2026:21:32:32 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6136 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
135.119.86.96 - - [24/Jun/2026:21:32:32 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6136 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
...
show less
Brute-Force
Anonymous
2026-06-24 13:13:03
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET /wp-json/wp/v2/users/ HTTP/1. ...
show more
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET /wp-json/wp/v2/users/ HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 13:11:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 135.119.86.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 135.119.86.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 09:11:40.922444 2026] [security2:error] [pid 17930:tid 17930] [client 135.119.86.96:2005] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||forefrontmusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "forefrontmusic.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajvXjMT3cSAeAa7jTnjQnAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 12:56:10
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 135.119.86.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 135.119.86.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 08:56:07.806979 2026] [security2:error] [pid 3710:tid 3710] [client 135.119.86.96:1412] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jessiedavison.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jessiedavison.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajvT551dOCbYpPpRVd5YCQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-06-24 12:53:56
(2 days ago)
135.119.86.96 - - [24/Jun/2026:14:53:55 +0200] "POST /xmlrpc.php HTTP/1.1" 403 5169 "-" "Mozilla/5.0 ...
show more
135.119.86.96 - - [24/Jun/2026:14:53:55 +0200] "POST /xmlrpc.php HTTP/1.1" 403 5169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack