๐บ๐ธ
TPI-Abuse
2025-11-06 19:50:40
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.146.35.174 (unn-156-146-35-174.cdn77.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 156.146.35.174 (unn-156-146-35-174.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 14:50:33.951530 2025] [security2:error] [pid 26293:tid 26410] [client 156.146.35.174:5762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jimlawrencesongs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jimlawrencesongs.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQz8CThCHCAsfLMOHnJVfgAAAlc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-10-02 04:24:41
(11 months ago)
1.624 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
myagent.site
2025-10-02 02:34:39
(11 months ago)
Blocking for trying to access an exploit file: /resources/my-home-didnt-sell-now-what/xmlrpc.php?rsd
Hacking
๐บ๐ธ
TPI-Abuse
2025-09-30 15:18:49
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 156.146.35.174 (unn-156-146-35-174.cdn77.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 156.146.35.174 (unn-156-146-35-174.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 30 11:18:45.422921 2025] [security2:error] [pid 27143:tid 27143] [client 156.146.35.174:40501] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eddyandvanessa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eddyandvanessa.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNv01Z8l2vvCgxQInsyLrAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-09-30 13:05:08
(11 months ago)
Blocking for trying to access an exploit file: /resources/property-marketing-plan/xmlrpc.php?rsd
Hacking
๐บ๐ธ
mnsf
2025-09-25 21:05:22
(1 year ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-25 08:49:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.146.35.174 (unn-156-146-35-174.cdn77.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 156.146.35.174 (unn-156-146-35-174.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 04:49:04.457437 2025] [security2:error] [pid 12088:tid 12088] [client 156.146.35.174:35643] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||camasmarket.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "camasmarket.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aNUCAAqVV-vSbXCB9CbRFQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
valryx
2025-09-10 03:26:53
(1 year ago)
๐ก๏ธ 156.146.35.174 - - [10/Sep/2025:03:26:51 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
๐ก๏ธ 156.146.35.174 - - [10/Sep/2025:03:26:51 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "156.146.35.174" "JP" "97cbd381790180f5-NRT"
...
show less
Web App Attack
๐ง๐ช
cmbplf
2025-08-09 10:21:06
(1 year ago)
1.078 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2025-07-19 14:40:04
(1 year ago)
IP banned by Fail2Ban in jail wordpress
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-15 22:10:17
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Vegascosmetics
2025-06-05 06:02:10
(1 year ago)
Kingcopy(AI-IDS):IP does Excessive BAD Request Abuse
Bad Web Bot
๐ฉ๐ช
Mykola Spesivtsev
2025-05-13 03:46:20
(1 year ago)
HTTP Tarpit detected bot activity:TargetPort:80, Path:/xmlrpc.php, Method:GET, UA:Mozilla/5.0 (Windo ...
show more
HTTP Tarpit detected bot activity:TargetPort:80, Path:/xmlrpc.php, Method:GET, UA:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.10
show less
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
Mykola Spesivtsev
2025-05-11 23:45:40
(1 year ago)
HTTP Tarpit detected bot activity:TargetPort:80, Path:/wp2/wp-includes/wlwmanifest.xml, Method:GET, ...
show more
HTTP Tarpit detected bot activity:TargetPort:80, Path:/wp2/wp-includes/wlwmanifest.xml, Method:GET, UA:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.10
show less
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
Mykola Spesivtsev
2025-05-11 23:45:40
(1 year ago)
HTTP Tarpit detected bot activity:TargetPort:80, Path:/shop/wp-includes/wlwmanifest.xml, Method:GET, ...
show more
HTTP Tarpit detected bot activity:TargetPort:80, Path:/shop/wp-includes/wlwmanifest.xml, Method:GET, UA:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.10
show less
Port Scan
Bad Web Bot
Web App Attack