Anonymous
2026-06-25 03:53:33
(1 day ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-25 03:29:00
(1 day ago)
8.892 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ฎ
YF
2026-06-25 03:00:39
(1 day ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐ฆ๐บ
Block Rockin' Beats
2026-06-25 02:10:04
(1 day ago)
Scanning for exploitable scripts
Hacking
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-06-25 01:59:09
(1 day ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /wp-json/wp/v2/users/ | Pays: US | UA: Mozilla/5.0 (Maci ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /wp-json/wp/v2/users/ | Pays: US | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:125.0) Gecko/20100101 Firefox/125.0
show less
Hacking
Web App Attack
๐ฉ๐ฐ
SaltySoftworks
2026-06-25 01:55:26
(1 day ago)
Page: /wp-json/wp/v2/users/
Hacking
Web App Attack
Anonymous
2026-06-25 01:46:51
(1 day ago)
[redacted] 172.212.160.48 - - [25/Jun/2026:03:46:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 656 "-" " ...
show more
[redacted] 172.212.160.48 - - [25/Jun/2026:03:46:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 656 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
[redacted] 172.212.160.48 - - [25/Jun/2026:03:46:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Brave/125"
[redacted] 172.212.160.48 - - [25/Jun/2026:03:46:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
[redacted] 172.212.160.48 - - [25/Jun/2026:03:46:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
[redacted] 172.212.160.48 - - [25/Jun/2026:03:46:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) A
...
show less
Hacking
Web App Attack
Anonymous
2026-06-25 01:30:04
(1 day ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
ArturShelby
2026-06-25 01:19:36
(1 day ago)
Honeypot triggered: /wp-json/wp/v2/users/
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 01:10:27
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 172.212.160.48 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 172.212.160.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 21:10:22.066577 2026] [security2:error] [pid 25327:tid 25327] [client 172.212.160.48:21874] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atame.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajx__nKoo_iMmJukeoODywAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-06-25 01:01:21
(1 day ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-06-25 00:54:02
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET /wp-json/wp/v2/users/ HTTP/1. ...
show more
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET /wp-json/wp/v2/users/ HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-06-25 00:45:48
(1 day ago)
[redacted] 172.212.160.48 - - [25/Jun/2026:02:45:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 656 "-" " ...
show more
[redacted] 172.212.160.48 - - [25/Jun/2026:02:45:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 656 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
[redacted] 172.212.160.48 - - [25/Jun/2026:02:45:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36 Edg/123.0.0.0"
[redacted] 172.212.160.48 - - [25/Jun/2026:02:45:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 OPR/110.0.0.0"
[redacted] 172.212.160.48 - - [25/Jun/2026:02:45:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0"
[redacted] 172.212.160.48 - - [25/Jun/2026:02:45:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 F
...
show less
Hacking
Web App Attack
๐ซ๐ท
RodGel
2026-06-25 00:45:34
(1 day ago)
High AbuseIPDB score: 75
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 00:42:52
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 172.212.160.48 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 172.212.160.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 20:42:46.518993 2026] [security2:error] [pid 30928:tid 30928] [client 172.212.160.48:21924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||biketurtlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "biketurtlehill.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajx5hvr3_QVP5eE5ncesSAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack