๐บ๐ธ
WeekendWeb
2025-10-06 21:38:12
(8 months ago)
Wordpress Vunerability attack
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-10-01 07:28:31
(8 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-09-30 15:42:22
(8 months ago)
[redacted] 156.253.175.193 - - [30/Sep/2025:17:42:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 449 "-" ...
show more
[redacted] 156.253.175.193 - - [30/Sep/2025:17:42:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 449 "-" "Mozilla/5.0 (iPad; U; CPU OS 4_3_3 like Mac OS X; de-de) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8J3 Safari/6533.18.5"
[redacted] 156.253.175.193 - - [30/Sep/2025:17:42:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 449 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 3.1)"
[redacted] 156.253.175.193 - - [30/Sep/2025:17:42:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 449 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0"
[redacted] 156.253.175.193 - - [30/Sep/2025:17:42:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 449 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0"
[redacted] 156.253.175.193 - - [30/Sep/2025:17:42:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 449 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1
...
show less
Hacking
Web App Attack
Anonymous
2025-09-29 00:33:41
(8 months ago)
WordPress Brute Force
Brute-Force
๐ซ๐ฎ
YF
2025-09-27 02:01:35
(9 months ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-24 18:22:52
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.175.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.175.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 14:22:44.780912 2025] [security2:error] [pid 24779:tid 24779] [client 156.253.175.193:29725] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webjemm.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webjemm.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aNQ29KVYEkouSS19pHI8ugAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2025-09-12 02:23:12
(9 months ago)
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-09-02 13:02:55
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 156.253.175.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 156.253.175.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 09:02:42.033459 2025] [security2:error] [pid 14860:tid 14860] [client 156.253.175.193:49749] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.teamulrich.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.teamulrich.com"] [uri "/"] [unique_id "aLbq8gvoGImuLA3UYHkH7QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2025-09-01 21:37:08
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2025-08-24 03:56:40
(10 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ZA/South Africa/-
Web App Attack
๐ณ๐ฑ
exxos
2025-08-23 16:03:01
(10 months ago)
Attacks with Bad user agents
Hacking
๐ฆ๐บ
weblite
2025-08-18 10:18:34
(10 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐บ๐ธ
fortypoundhead
2025-08-17 10:55:32
(10 months ago)
SQL Injection Attempt
SQL Injection
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2025-08-17 00:43:15
(10 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ZA/South Africa/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-28 17:23:10
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.175.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.175.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 28 13:23:04.415300 2025] [security2:error] [pid 2154321:tid 2154321] [client 156.253.175.193:10919] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||owenbiosci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "owenbiosci.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aGAk-G7zZ04RI2JrWAaIVwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack