๐ฉ๐ช
on-com
2026-07-21 16:15:01
(17 hours ago)
URL scan
Brute-Force
Web App Attack
๐ฉ๐ช
webanyone
2026-07-21 15:15:53
(18 hours ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฉ๐ช
neckaralb-admin.de
2026-07-21 14:28:16
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-07-21 14:14:53
(19 hours ago)
Excessive HTTP request rate
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 14:13:22
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.65.243.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.65.243.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 10:13:15.789935 2026] [security2:error] [pid 854:tid 854] [client 159.65.243.120:58077] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gisur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gisur.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al9-ewhyi4_6pdQXKnVeZgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-21 13:21:12
(20 hours ago)
[TueJul2115:21:08.9209072026][security2:error][pid2152602:tid2152636][client159.65.243.120:0]ModSecu ...
show more
[TueJul2115:21:08.9209072026][security2:error][pid2152602:tid2152636][client159.65.243.120:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"edilmarra.ch\"][uri\"/xmlrpc.php\"][unique_id\"al9yRIcEaFBmHh4SCqIYLwAAABg\"]
show less
Hacking
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-07-21 13:12:28
(20 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
Anonymous
2026-07-21 13:11:00
(20 hours ago)
159.65.243.120 - - [21/Jul/2026:21:11:00 +0800] "GET //xmlrpc.php?rsd HTTP/1.1" 404 296523 "-" "Mozi ...
show more
159.65.243.120 - - [21/Jul/2026:21:11:00 +0800] "GET //xmlrpc.php?rsd HTTP/1.1" 404 296523 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-21 13:05:18
(21 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ช๐ธ
tg_de
2026-07-21 12:51:01
(21 hours ago)
18 attempts since 21.07.2026 12:50:59 UTC - last search for: //sito/wp-includes/wlwmanifest.xml
Web App Attack
๐ฉ๐ช
LRob
2026-07-21 12:48:57
(21 hours ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Appl ...
show more
CrowdSec: lrob/wp-xmlrpc-bf | req: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-21 12:48:32
(21 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:48:14
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.65.243.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.65.243.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:48:10.871841 2026] [security2:error] [pid 421119:tid 421119] [client 159.65.243.120:51645] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eatcakecup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eatcakecup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al9qilFdaGF4mC5I2mKA6wAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-21 11:56:57
(22 hours ago)
Try to access /xmlrpc.php?rsd
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:44:12
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 159.65.243.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.65.243.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:44:05.246058 2026] [security2:error] [pid 31229:tid 31229] [client 159.65.243.120:62633] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drwolberg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drwolberg.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al9bhZx36H3AOHyzn0by6AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack