๐ฉ๐ช
Elygor77
2026-07-24 06:52:03
(3 days ago)
WordPress xmlrpc.php brute-force: 29 malicious requests observed (auto-report via server-monitor).
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:25:56
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 150.228.61.77 (customer.sfiabgr1.isp.starlink.c ...
show more
(mod_security) mod_security (id:225170) triggered by 150.228.61.77 (customer.sfiabgr1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:25:51.624970 2026] [security2:error] [pid 3948839:tid 3948839] [client 150.228.61.77:55181] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||broneksuchanek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "broneksuchanek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amMFb2eTFRDES0gkZHCzcgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-07-23 21:20:11
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from GR.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (P ...
show more
Triggered Cloudflare WAF (firewallCustom) from GR.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (POST) | Endpoint: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/73.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
ambor
2026-07-23 18:40:13
(4 days ago)
Attack type: wordpress_attack_attempt | Target: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; x86) ...
show more
Attack type: wordpress_attack_attempt | Target: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537 | Method: POST | Country: GR
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-23 15:16:06
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 150.228.61.77 (customer.sfiabgr1.isp.starlink.c ...
show more
(mod_security) mod_security (id:225170) triggered by 150.228.61.77 (customer.sfiabgr1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 11:16:00.206429 2026] [security2:error] [pid 8089:tid 8089] [client 150.228.61.77:7188] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||learnserve.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "learnserve.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amIwMEJereoMhp6QGJ5NjQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-22 11:57:58
(5 days ago)
[WedJul2213:57:56.4163902026][security2:error][pid367849:tid367981][client150.228.61.77:0]ModSecurit ...
show more
[WedJul2213:57:56.4163902026][security2:error][pid367849:tid367981][client150.228.61.77:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"scrspace.com\"][uri\"/xmlrpc.php\"][unique_id\"amCwROjak-mK88Fr1D2lhwAAABM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-22 06:21:39
(5 days ago)
(wordpress) Failed wordpress login from 150.228.61.77 (GR/Greece/customer.sfiabgr1.isp.starlink.com)
Brute-Force
๐ฉ๐ช
findlab
2026-07-21 23:35:01
(6 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack