|
๐ณ๐ฑ
applemooz
|
|
WordPress XMLRPC Brute Force Attacks
...
|
Brute-Force
Web App Attack
|
|
|
๐ณ๐ฑ
applemooz
|
|
WordPress XMLRPC Brute Force Attacks
...
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
Jason Howell
|
|
156.240.99.50 - - [05/Oct/2025:21:14:08 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3293 "-" "Mozilla/4.0 ...
show more
156.240.99.50 - - [05/Oct/2025:21:14:08 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3293 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; InfoPath.1)"
156.240.99.50 - - [05/Oct/2025:21:14:24 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3292 "-" "Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_3_2 like Mac OS X; en-us) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8H7 Safari/6533.18.5"
156.240.99.50 - - [05/Oct/2025:21:14:31 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3293 "-" "Mozilla/5.0 (iPad; CPU OS 11_3_1 like Mac OS X) AppleWebKit/604.1.34 (KHTML, like Gecko) GSA/51.0.198805899 Mobile/15E302 Safari/604.1"
156.240.99.50 - - [05/Oct/2025:21:14:37 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3292 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/534.30 (KHTML, like Gecko) Ubuntu/11.04 Chromium/12.0.742.112 Chrome/12.0.742.112 Safari/534.30"
156.240.99.50 - - [05/Oct/2025:21:14:47 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3293 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64
...
show less
|
Web App Attack
|
|
|
๐ฉ๐ช
Marc
|
|
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 156.240.99.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.240.99.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 05:16:13.922395 2025] [security2:error] [pid 24334:tid 24334] [client 156.240.99.50:19635] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yourbrandhere.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yourbrandhere.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aNzxXbDedi6_S5J3AaptzwAAAE4"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
[redacted] 156.240.99.50 - - [30/Sep/2025:17:35:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 447 "-" "M ...
show more
[redacted] 156.240.99.50 - - [30/Sep/2025:17:35:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 447 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)"
[redacted] 156.240.99.50 - - [30/Sep/2025:17:35:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 447 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G570M Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 [FB_IAB/FB4A;FBAV/196.0.0.41.95;]"
[redacted] 156.240.99.50 - - [30/Sep/2025:17:35:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 447 "-" "Mozilla/5.0 (Linux; Android 7.1.2; Redmi 4X Build/N2G47H) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.111 Mobile Safari/537.36"
[redacted] 156.240.99.50 - - [30/Sep/2025:17:35:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 447 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10"
[redacted] 156.240.99.50 - - [30/Sep/2025:17:35:
...
show less
|
Hacking
Web App Attack
|
|
|
Anonymous
|
|
WordPress Brute Force
|
Brute-Force
|
|
|
๐ฆ๐บ
AWW-Admin
|
|
(wordpress) Failed wordpress login from 156.240.99.50 (FR/France/-)
|
Brute-Force
|
|
|
๐ซ๐ฎ
YF
|
|
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
applemooz
|
|
WordPress XMLRPC Brute Force Attacks
...
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
Ba-Yu
|
|
WP-xmlrpc exploit
|
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
|
|
|
๐ฆ๐บ
screwlooseit.com.au
|
|
Blocked by CSF 13 firewall - Rule: XMLRPC
ZA/South Africa/-
|
Web App Attack
|
|
|
๐ช๐ธ
10dencehispahard SL
|
|
WP probing for vulnerabilities
|
Hacking
Exploited Host
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 156.240.99.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.240.99.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 30 23:21:05.900285 2025] [security2:error] [pid 16041:tid 16041] [client 156.240.99.50:45837] [client 156.240.99.50] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||manaplas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "manaplas.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-oKIRTpL4L6qx9rTrG7TgAAABU"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 156.240.99.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 156.240.99.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 28 01:07:42.928536 2025] [security2:error] [pid 21100:tid 21100] [client 156.240.99.50:19321] [client 156.240.99.50] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||synergystudios.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "synergystudios.org"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-YunmW0UPtB-wkjj_1PpAAAAAE"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|