๐ณ๐ฑ
applemooz
2025-10-07 14:29:00
(1 year ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ฉ๐ช
applemooz
2025-09-27 06:07:05
(1 year ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ฉ๐ช
bsoft.de
2025-09-08 02:11:12
(1 year ago)
154.213.196.9 - - [08/Sep/2025:03:28:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 ...
show more
154.213.196.9 - - [08/Sep/2025:03:28:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.44 Safari/537.36"
154.213.196.9 - - [08/Sep/2025:03:41:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0"
154.213.196.9 - - [08/Sep/2025:04:11:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0; Trident/5.0)"
show less
Web App Attack
๐ฆ๐บ
weblite
2025-09-01 21:53:05
(1 year ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฉ๐ช
dayda.net
2025-08-29 17:38:38
(1 year ago)
query: resetpwd'
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-31 14:42:33
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 31 10:42:28.733591 2025] [security2:error] [pid 28341:tid 28341] [client 154.213.196.9:24073] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||corstratinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "corstratinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIuA1GWAiZYPHZXU5ffBGQAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-17 01:52:42
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-07-16 06:06:28
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 16 02:06:23.446659 2025] [security2:error] [pid 7760:tid 7760] [client 154.213.196.9:35449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||belindalloyd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "belindalloyd.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aHdBXzUSr9JaqezbTA6EugAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-16 04:45:52
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 16 00:45:44.002821 2025] [security2:error] [pid 10446:tid 10446] [client 154.213.196.9:43483] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||areafinancieratf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "areafinancieratf.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aHcudwnmifj8Y9padxHPvgAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
uira.live
2025-05-04 15:54:45
(1 year ago)
Malicious activity detected from 200373 DREI-K-TECH-GMBH towards host uira.live (GET HTTP/2) @ 2025- ...
show more
Malicious activity detected from 200373 DREI-K-TECH-GMBH towards host uira.live (GET HTTP/2) @ 2025-05-04T15:54:45Z (1 occurrences)
show less
DDoS Attack
Anonymous
2025-04-30 16:56:08
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-03-31 07:26:14
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 31 03:26:09.991616 2025] [security2:error] [pid 19418:tid 19418] [client 154.213.196.9:9411] [client 154.213.196.9] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hotjive.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hotjive.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-pDkfSwC1SW4JJ3U_JkCwAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-03-26 14:08:01
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-03-24 22:35:14
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 18:35:09.685320 2025] [security2:error] [pid 22836:tid 22836] [client 154.213.196.9:17667] [client 154.213.196.9] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kwijlen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kwijlen.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-HeHaGzrv_HJTlm9p8_pgAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-24 09:10:25
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.196.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 05:10:19.235779 2025] [security2:error] [pid 30444:tid 30444] [client 154.213.196.9:37589] [client 154.213.196.9] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||randyshelly.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "randyshelly.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-Ehe_Y8AyTLCzl5Onp06gAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack