๐ณ๐ฑ
applemooz
2025-10-06 06:10:32
(8 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-05 04:15:18
(8 months ago)
(mod_security) mod_security (id:210831) triggered by 154.213.199.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 154.213.199.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 00:15:13.818973 2025] [security2:error] [pid 24136:tid 24136] [client 154.213.199.125:34481] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||geckoturner.com|F|4"] [data "compatible ; MSIE"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "geckoturner.com"] [uri "/xmlrpc.php"] [unique_id "aOHw0Qj9smaMj0NeUfFPkQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2025-09-26 18:00:33
(8 months ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-15 04:04:53
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
Rip
2025-09-13 05:44:41
(9 months ago)
Apache Authentication attack. CMS Brute Force - Access Forbidden
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2025-09-12 01:19:31
(9 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 20:02:31
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.199.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.199.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 16:02:25.267708 2025] [security2:error] [pid 17928:tid 17928] [client 154.213.199.125:56491] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.argentinas.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMMq0YDVoOVYuhQzP1yPJAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 21:08:57
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.199.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.199.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 17:08:52.964825 2025] [security2:error] [pid 3510:tid 3532] [client 154.213.199.125:32823] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.deathconfusion.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.deathconfusion.com"] [uri "/s3cmd.ini"] [unique_id "aMHo5HyoTIQiOJuqG6H3jQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bsoft.de
2025-09-08 01:52:41
(9 months ago)
154.213.199.125 - - [08/Sep/2025:03:20:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5. ...
show more
154.213.199.125 - - [08/Sep/2025:03:20:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419.3 (KHTML, like Gecko) Safari/419.3"
154.213.199.125 - - [08/Sep/2025:03:21:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_3 like Mac OS X) AppleWebKit/604.1.34 (KHTML, like Gecko) CriOS/69.0.3497.105 Mobile/15E148 Safari/604.1"
154.213.199.125 - - [08/Sep/2025:03:52:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_2_1 like Mac OS X) AppleWebKit/604.1.34 (KHTML, like Gecko) CriOS/63.0.3239.73 Mobile/15C153 Safari/604.1"
show less
Web App Attack
๐ฆ๐บ
weblite
2025-09-02 05:33:48
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-31 22:36:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.199.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.199.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 18:36:50.635255 2025] [security2:error] [pid 5558:tid 5558] [client 154.213.199.125:30721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.digi-estudio.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLTOglZBYoFHw6cP6l-xmAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-25 16:22:19
(9 months ago)
wordpress authentication brute force
Brute-Force
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-08-23 18:41:29
(9 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
hostseries
2025-05-11 17:13:36
(1 year ago)
Brute-force cPanel Services
Brute-Force
๐บ๐ธ
COMPLEX
2025-05-10 17:40:36
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: MANAGED_CHALLENGE
ASN: 200373 (DREI ...
show more
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: MANAGED_CHALLENGE
ASN: 200373 (DREI-K-TECH-GMBH)
Protocol: HTTP/2 (GET method)
Timestamp: 2025-05-10T17:37:11Z
show less
Bad Web Bot