๐ช๐ธ
masterguru
2026-06-25 02:06:23
(3 days ago)
(xmlrpc) Failed xmlrpc access from 135.232.208.130 (US/United States/-): 5 in the last 3600 secs (0- ...
show more
(xmlrpc) Failed xmlrpc access from 135.232.208.130 (US/United States/-): 5 in the last 3600 secs (0-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-25 02:04:32
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:04:25.843492 2026] [security2:error] [pid 9674:tid 9674] [client 135.232.208.130:13399] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||valbreniscrivalbo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "valbreniscrivalbo.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajyMqdDPVwYJYtcOWKhpSgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 01:24:26
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 21:24:19.286664 2026] [security2:error] [pid 18907:tid 18907] [client 135.232.208.130:14863] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||christianbroadcastingleague.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "christianbroadcastingleague.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajyDQwqY2PR32y3QovkXHgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Holger
2026-06-25 01:17:27
(3 days ago)
WordPress WebAttack
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-25 01:07:46
(3 days ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 135.232.208.130 (US/United States/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 135.232.208.130 (US/United States/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
integrantservices.com
2026-06-25 00:43:06
(3 days ago)
(wordpress) Failed wordpress login from 135.232.208.130 (US/United States/-)
Brute-Force
๐ซ๐ท
applemooz
2026-06-25 00:42:41
(3 days ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 00:31:04
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 20:31:00.683172 2026] [security2:error] [pid 30920:tid 30920] [client 135.232.208.130:14720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||badwaterclaims.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "badwaterclaims.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajx2xFURCGgG__xosn-p2wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-06-25 00:07:49
(3 days ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /wp-json/wp/v2/users/ | Pays: US | UA: Mozilla/5.0 (Maci ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /wp-json/wp/v2/users/ | Pays: US | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 00:07:10
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 20:07:05.139656 2026] [security2:error] [pid 26593:tid 26593] [client 135.232.208.130:14852] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||williambarfoot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "williambarfoot.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajxxKeUJvo5BwJo4OtQ2mAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ParaBug
2026-06-25 00:02:46
(3 days ago)
135.232.208.130 - - [25/Jun/2026:02:02:45 +0200] "GET /wp-json/wp/v2/users/ HTTP/1.1" 301 4715 "-" " ...
show more
135.232.208.130 - - [25/Jun/2026:02:02:45 +0200] "GET /wp-json/wp/v2/users/ HTTP/1.1" 301 4715 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Vivaldi/6.7"
...
show less
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
ArturShelby
2026-06-24 23:55:03
(3 days ago)
Honeypot triggered: /wp-json/wp/v2/users/
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-06-24 23:39:32
(3 days ago)
CMS/framework probe: 135.232.208.130 - - [25/Jun/2026:01:39:31 +0200] "GET /wp-json/wp/v2/users/ HTT ...
show more
CMS/framework probe: 135.232.208.130 - - [25/Jun/2026:01:39:31 +0200] "GET /wp-json/wp/v2/users/ HTTP/1.1" 404 8690 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" asn=8075 org="Microsoft Corporation" country=US
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 23:38:48
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 135.232.208.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 19:38:42.529914 2026] [security2:error] [pid 1745:tid 1745] [client 135.232.208.130:14043] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gamedayincentives.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gamedayincentives.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajxqghT0IeauCBlR4h0ZNQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 23:32:42
(3 days ago)
Bad Web Bot
Web App Attack