π³π±
applemooz
2025-10-07 13:54:30
(8 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
π³π±
applemooz
2025-10-06 04:05:24
(8 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-05 10:48:46
(8 months ago)
(mod_security) mod_security (id:210831) triggered by 156.253.178.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 156.253.178.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 06:48:40.929728 2025] [security2:error] [pid 28743:tid 28743] [client 156.253.178.79:48839] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||thenursingsite.com|F|4"] [data "compatible ; MSIE"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "thenursingsite.com"] [uri "/xmlrpc.php"] [unique_id "aOJNCAZuMdBMPR6ZCVD6tQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-05 07:10:33
(8 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
π©πͺ
Marc
2025-10-05 06:11:51
(8 months ago)
Brute-Force
Anonymous
2025-09-29 00:26:46
(8 months ago)
WordPress Brute Force
Brute-Force
π¦πΊ
AWW-Admin
2025-09-28 07:20:44
(8 months ago)
(wordpress) Failed wordpress login from 156.253.178.79 (FR/France/-)
Brute-Force
Anonymous
2025-09-20 04:47:14
(9 months ago)
[redacted] 156.253.178.79 - - [20/Sep/2025:06:47:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" " ...
show more
[redacted] 156.253.178.79 - - [20/Sep/2025:06:47:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:32.0) Gecko/20100101 Firefox/32.0"
[redacted] 156.253.178.79 - - [20/Sep/2025:06:47:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (iPad; U; CPU OS 5_0_1 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B334b Safari/531.21.10"
[redacted] 156.253.178.79 - - [20/Sep/2025:06:47:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (iPad; CPU OS 7_1 like Mac OS X) AppleWebKit/537.51.2 (KHTML, like Gecko) Version/7.0 Mobile/11D167 Safari/9537.53"
[redacted] 156.253.178.79 - - [20/Sep/2025:06:47:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Linux; Android 8.0.0; WAS-LX3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.80 Mobile Safari/537.36"
[redacted] 156.253.178.79 - - [20/Sep/20
...
show less
Hacking
Web App Attack
π¦πΊ
AWW-Admin
2025-09-12 19:05:40
(9 months ago)
(wordpress) Failed wordpress login from 156.253.178.79 (FR/France/-)
Brute-Force
π©πͺ
bsoft.de
2025-09-08 02:30:11
(9 months ago)
156.253.178.79 - - [08/Sep/2025:03:29:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 ...
show more
156.253.178.79 - - [08/Sep/2025:03:29:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.71 Safari/537.36"
156.253.178.79 - - [08/Sep/2025:04:01:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36"
156.253.178.79 - - [08/Sep/2025:04:30:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Windows NT 6.0; WOW64; rv:46.0) Gecko/20100101 Firefox/46.0"
show less
Web App Attack
π©πͺ
Ba-Yu
2025-08-25 03:41:33
(9 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
πΊπΈ
island-freaks.com
2025-08-09 11:16:22
(10 months ago)
Attack Type: WordPress Exploit Bot attempt on /wp-json/wp/v2/users | DNS 156.253.178.79 | Agent: Moz ...
show more
Attack Type: WordPress Exploit Bot attempt on /wp-json/wp/v2/users | DNS 156.253.178.79 | Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Port Scan
Hacking
Bad Web Bot
Exploited Host
Web App Attack
π¦πΊ
weblite
2025-07-31 16:30:16
(10 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
Anonymous
2025-06-30 06:04:20
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π©πͺ
Ba-Yu
2025-06-29 16:49:00
(11 months ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack