๐บ๐ธ
TPI-Abuse
2026-06-05 15:10:26
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 136.117.57.77 (77.57.117.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.117.57.77 (77.57.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 11:10:20.163369 2026] [security2:error] [pid 4582:tid 4582] [client 136.117.57.77:62853] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paulshorrock.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paulshorrock.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiLm3EXNOFtOFI5qI3cvCAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Anytech
2026-06-05 15:05:15
(6 days ago)
Blocked by Conn-Monitor: Web scanning activity
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 14:37:53
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 136.117.57.77 (77.57.117.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.117.57.77 (77.57.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:37:47.737757 2026] [security2:error] [pid 26255:tid 26255] [client 136.117.57.77:64466] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||promoadvocate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "promoadvocate.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "aiLfO1-nr9HTeT8kw3JTMgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-06-05 14:28:15
(6 days ago)
external host: 136.117.57.77 - - [05/Jun/2026:16:28:14 +0200] "GET //wp-includes/ID3/license.txt HTT ...
show more
external host: 136.117.57.77 - - [05/Jun/2026:16:28:14 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 5663 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" CF-Ray:- CF-IP:-
show less
Web App Attack
Anonymous
2026-06-05 14:28:13
(6 days ago)
Attac
Brute-Force
๐ซ๐ท
applemooz
2026-06-05 14:20:15
(6 days ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 14:12:48
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 136.117.57.77 (77.57.117.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.117.57.77 (77.57.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:12:42.513148 2026] [security2:error] [pid 29375:tid 29375] [client 136.117.57.77:59789] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "schlegelcreative.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiLZWgMQvpErspnBbVyz4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-05 14:05:31
(6 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ฉ๐ช
KiekerJan
2026-06-05 14:03:57
(6 days ago)
136.117.57.77 - - [05/Jun/2026:16:03:56 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
136.117.57.77 - - [05/Jun/2026:16:03:56 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.117.57.77 - - [05/Jun/2026:16:03:56 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-06-05 14:00:04
(6 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
Anonymous
2026-06-05 13:59:04
(6 days ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-06-05 13:56:51
(6 days ago)
[ns65.kdns.gr] httpd-xmlrpc-post: sites=hatzifotis.gr; logs=/var/log/httpd/domains/hatzifotis.gr.log ...
show more
[ns65.kdns.gr] httpd-xmlrpc-post: sites=hatzifotis.gr; logs=/var/log/httpd/domains/hatzifotis.gr.log; samples=//xmlrpc.php
show less
Brute-Force
Web App Attack
๐จ๐ญ
zynex
2026-06-05 13:49:08
(6 days ago)
URL Probing: /wp1/wp-includes/wlwmanifest.xml
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-05 13:49:01
(6 days ago)
trying wp-login.php/xmlrpc.php 74 times in 1 minutes
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-05 13:47:52
(6 days ago)
Try to access /xmlrpc.php?rsd
Web App Attack