|
๐บ๐ธ
WeekendWeb
|
|
Wordpress Vunerability attack
|
Web App Attack
|
|
|
Anonymous
|
|
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
|
Hacking
Web App Attack
|
|
|
๐ซ๐ฎ
YF
|
|
xmlrpc.php (Potential DDoS or brute force)
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
[redacted] 156.253.168.2 - - [20/Sep/2025:06:52:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "M ...
show more
[redacted] 156.253.168.2 - - [20/Sep/2025:06:52:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Linux; Android 6.0; CAM-L03 Build/HUAWEICAM-L03) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Mobile Safari/537.36"
[redacted] 156.253.168.2 - - [20/Sep/2025:06:52:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)"
[redacted] 156.253.168.2 - - [20/Sep/2025:06:52:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_4_11; en) AppleWebKit/525.18 (KHTML, like Gecko) Version/3.1.2 Safari/525.22"
[redacted] 156.253.168.2 - - [20/Sep/2025:06:52:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0"
[redacted] 156.253.168.2 - - [20/Sep/2025:06:52:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 156.253.168.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.168.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 16:59:35.381252 2025] [security2:error] [pid 3510:tid 3513] [client 156.253.168.2:9979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deathbyaudioorg.killerrockandroll.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMHmt3yoTIQiOJuqG6H1yAAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 156.253.168.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 06:52:53.446717 2025] [security2:error] [pid 30799:tid 30799] [client 156.253.168.2:23507] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.adn-media.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.adn-media.net"] [uri "/s3cmd.ini"] [unique_id "aL1kBbge9vEQmoi3503xlgAAABQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 156.253.168.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.168.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 14:45:44.128689 2025] [security2:error] [pid 31175:tid 31175] [client 156.253.168.2:40731] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cook-islands-boat-registration.com.boatregistrationdelaware.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cook-islands-boat-registration.com.boatregistrationdelaware.com"] [uri "/s3cmd.ini"] [unique_id "aLSYWJTd0b6rHub8gDyLQgAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
webgobe
|
|
wew-(rsform) : try to access forms...
|
Hacking
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐บ๐ธ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|