🇳🇴
jad-abuse
2026-07-21 17:26:16
(5 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
🇧🇾
lns.bz
2026-07-20 20:24:09
(6 days ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
🇩🇪
filstal.org
2026-07-19 22:51:10
(1 week ago)
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. U ...
show more
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. UA: Mozilla/5.0 (Linux; Android 10; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/60.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-19 21:45:15
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 177.44.177.193 (177-44-177-193.sobralnet.net.br ...
show more
(mod_security) mod_security (id:225170) triggered by 177.44.177.193 (177-44-177-193.sobralnet.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 17:45:10.339177 2026] [security2:error] [pid 4026968:tid 4026968] [client 177.44.177.193:49812] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eta-mct.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eta-mct.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al1FZvbWqaYbL2pZvp_AiQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-19 20:30:58
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇳🇿
Tripwire
2026-07-19 16:41:39
(1 week ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-19 10:35:51
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 177.44.177.193 (177-44-177-193.sobralnet.net.br ...
show more
(mod_security) mod_security (id:225170) triggered by 177.44.177.193 (177-44-177-193.sobralnet.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 06:35:47.398580 2026] [security2:error] [pid 32424:tid 32424] [client 177.44.177.193:49809] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||btsalesrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "btsalesrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alyogwYXTTTA6sHh_56CRAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-07-18 23:24:07
(1 week ago)
[SunJul1901:24:02.5769682026][security2:error][pid4146099:tid4146116][client177.44.177.193:0]ModSecu ...
show more
[SunJul1901:24:02.5769682026][security2:error][pid4146099:tid4146116][client177.44.177.193:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"schneider-tools.ch\"][uri\"/xmlrpc.php\"][unique_id\"alwLEtOfuEBVdTrpdZzZ3wAAAM0\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇦
Olexiy Backend
2026-07-18 12:25:34
(1 week ago)
177.44.177.193
...
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-18 08:23:01
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 177.44.177.193 (177-44-177-193.sobralnet.net.br ...
show more
(mod_security) mod_security (id:225170) triggered by 177.44.177.193 (177-44-177-193.sobralnet.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 04:22:53.767257 2026] [security2:error] [pid 1052925:tid 1052925] [client 177.44.177.193:11247] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||xyncom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "xyncom.com"] [uri "/wp-json/wp/v2/users"] [unique_id "als33WKwWJ8R9Tau2MEsEgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack