๐ฆ๐บ
AWW-Admin
2025-09-24 00:55:20
(8 months ago)
(wordpress) Failed wordpress login from 156.233.74.101 (BR/Brazil/-)
Brute-Force
๐ซ๐ฎ
YF
2025-09-23 20:01:04
(8 months ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
๐บ๐ธ
Rip
2025-09-13 05:47:29
(9 months ago)
Apache Authentication attack. CMS Brute Force - Access Forbidden
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2025-09-12 02:51:27
(9 months ago)
Brute-Force
๐ฉ๐ช
bsoft.de
2025-09-08 02:40:56
(9 months ago)
156.233.74.101 - - [08/Sep/2025:03:42:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 ...
show more
156.233.74.101 - - [08/Sep/2025:03:42:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0"
156.233.74.101 - - [08/Sep/2025:04:10:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 8_1_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/5.1.42378 Mobile/12B440 Safari/600.1.4"
156.233.74.101 - - [08/Sep/2025:04:40:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_7; en-us) AppleWebKit/530.19.2 (KHTML, like Gecko) Version/4.0.2 Safari/530.19"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 03:13:32
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 05 23:13:28.134491 2025] [security2:error] [pid 3395:tid 3395] [client 156.233.74.101:16175] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.go-rfi.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.go-rfi.com"] [uri "/s3cmd.ini"] [unique_id "aLum2DX15CYKLfU0itFTwgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2025-09-02 06:14:28
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 20:18:15
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 16:18:09.424003 2025] [security2:error] [pid 11751:tid 11751] [client 156.233.74.101:58841] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.elissazeches.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.elissazeches.com"] [uri "/s3cmd.ini"] [unique_id "aLX_gfYXg1077aNpnENEsgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-31 07:46:33
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 03:46:28.994017 2025] [security2:error] [pid 2474:tid 2491] [client 156.233.74.101:9049] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.e819.kylight.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.e819.kylight.com"] [uri "/s3cmd.ini"] [unique_id "aLP91Dme3rWDJmijNh8aYgAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-27 20:15:06
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 27 16:15:00.513940 2025] [security2:error] [pid 4359:tid 4359] [client 156.233.74.101:13073] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zodiacwin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zodiacwin.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aK9nRJS5_EW9TwaYuKM3dgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-08-25 04:38:08
(9 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
Anonymous
2025-08-17 04:20:39
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ช๐ธ
el-brujo
2025-03-30 15:26:43
(1 year ago)
[Sun Mar 30 17:26:34.227002 2025] [proxy_fcgi:error] [pid 887889:tid 888695] [remote 156.233.74.101: ...
show more
[Sun Mar 30 17:26:34.227002 2025] [proxy_fcgi:error] [pid 887889:tid 888695] [remote 156.233.74.101:0] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
[Sun Mar 30 17:26:42.427924 2025] [proxy_fcgi:error] [pid 887889:tid 888445] [remote 156.233.74.101:0] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-03-30 15:26:33
(1 year ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: ns2.elhacker.net userAgent: Apache-H ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: ns2.elhacker.net userAgent: Apache-HttpClient/4.5.13 (Java/11.0.26) Action: managed_challenge Source: firewallManaged ASN Description: DREI-K-TECH-GMBH Country: BR Method: POST Timestamp: 2025-03-30T15:26:33Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 20:35:12
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 156.233.74.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 16:35:06.863943 2025] [security2:error] [pid 15898:tid 15898] [client 156.233.74.101:37369] [client 156.233.74.101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dianamead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dianamead.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-Rk-uc2N1TDj4jHTg0n6wAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack