๐บ๐ธ
TPI-Abuse
2026-07-27 19:49:53
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 164.163.14.24 (ip-164.163.14.24.dtel.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 164.163.14.24 (ip-164.163.14.24.dtel.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 15:49:45.469446 2026] [security2:error] [pid 23005:tid 23066] [client 164.163.14.24:31652] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sweeneyzone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sweeneyzone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ame2WdSpO-XBO8RPSrn8jgAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-27 15:16:38
(9 hours ago)
[MonJul2717:16:33.1138722026][security2:error][pid3131142:tid3131177][client164.163.14.24:0]ModSecur ...
show more
[MonJul2717:16:33.1138722026][security2:error][pid3131142:tid3131177][client164.163.14.24:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"miotrentino.it\"][uri\"/xmlrpc.php\"][unique_id\"amd2US9PRRjW8T3IO7kWYwAAABg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 14:42:52
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 164.163.14.24 (ip-164.163.14.24.dtel.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 164.163.14.24 (ip-164.163.14.24.dtel.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:42:47.872194 2026] [security2:error] [pid 2377:tid 2377] [client 164.163.14.24:32221] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||latentpixel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "latentpixel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amduZx4OgHL4YznzDFvvZQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-07-26 17:11:19
(1 day ago)
Honeypot access: WordPress XML-RPC attack attempt. Path: /xmlrpc.php
Brute-Force
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-26 16:12:14
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 15:47:07
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 164.163.14.24 (ip-164.163.14.24.dtel.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 164.163.14.24 (ip-164.163.14.24.dtel.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 11:47:01.453123 2026] [security2:error] [pid 3940581:tid 3940581] [client 164.163.14.24:31408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daisydoesoap.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daisydoesoap.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amYr9dcNeKr5pEdUkRpfOgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-07-26 13:27:46
(1 day ago)
164.163.14.24 - - [26/Jul/2026:21:24:36 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5892 "-" "Mozilla/5.0 ...
show more
164.163.14.24 - - [26/Jul/2026:21:24:36 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5892 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/76.0.0.0 Safari/537.36"
164.163.14.24 - - [26/Jul/2026:21:27:11 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5892 "-" "Mozilla/5.0 (Windows NT 10.0; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/86.0.0.0 Safari/537.36"
164.163.14.24 - - [26/Jul/2026:21:27:45 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5892 "-" "Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/80.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ฉ๐ช
4server
2026-07-25 16:07:41
(2 days ago)
[SatJul2518:07:37.3116042026][security2:error][pid115443:tid115478][client164.163.14.24:0]ModSecurit ...
show more
[SatJul2518:07:37.3116042026][security2:error][pid115443:tid115478][client164.163.14.24:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"brunocampagna.com\"][uri\"/xmlrpc.php\"][unique_id\"amTfSSbCv-7cH9ZSyHlLdgAAABg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-07-10 00:06:45
(2 weeks ago)
block ruleset A5EE6C8F745F0934168261886A3817E5C386412A
Bad Web Bot
๐ณ๐ฑ
exxos
2025-08-08 18:10:21
(11 months ago)
HTTP1.x attacks
DDoS Attack
๐ณ๐ฑ
exxos
2025-08-06 07:03:01
(11 months ago)
http-no-verb
Hacking