Anonymous
2026-07-20 08:35:15
(4 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐จ๐ญ
4server
2026-07-19 22:29:05
(14 hours ago)
[MonJul2000:28:58.7056082026][security2:error][pid2930196:tid2930231][client179.189.78.232:0]ModSecu ...
show more
[MonJul2000:28:58.7056082026][security2:error][pid2930196:tid2930231][client179.189.78.232:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"fisioterapiafalzone.ch\"][uri\"/xmlrpc.php\"][unique_id\"al1PqsYqzRoB2MYJ_MLoDgAAARc\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
rh24
2026-07-19 15:15:13
(21 hours ago)
(xmlrpc_405) XMLRPC-Bot 405 179.189.78.232 (BR/Brazil/179-189-78-232.cgnat.adyl.net.br)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-19 03:41:57
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.b ...
show more
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 23:41:52.918050 2026] [security2:error] [pid 2938891:tid 2938891] [client 179.189.78.232:56651] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||timetemple.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "timetemple.org"] [uri "/wp-json/wp/v2/users"] [unique_id "alxHgHrna9v_76TYAAXbVQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 19:36:05
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.b ...
show more
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 15:35:55.388149 2026] [security2:error] [pid 32208:tid 32208] [client 179.189.78.232:54538] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||odysseydogasporlari.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "odysseydogasporlari.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alvVm-5oynkVRQL36RWvugAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Flo Flo
2026-07-18 13:29:59
(1 day ago)
179.189.78.232 - - - [18/Jul/2026:15:29:58 +0200] "flad.xyz" "POST /xmlrpc.php HTTP/1.1" 444 0 "-" " ...
show more
179.189.78.232 - - - [18/Jul/2026:15:29:58 +0200] "flad.xyz" "POST /xmlrpc.php HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/79.0.0.0 Safari/537.36" 0.000
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-07-18 06:22:27
(2 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 179.189.78.232 (BR/Brazil/179-189-78-232.cgnat.adyl.net.b ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 179.189.78.232 (BR/Brazil/179-189-78-232.cgnat.adyl.net.br): 10 in the last 3600 secs (0-201)
show less
Hacking
๐ฆ๐บ
afleventoffice.com.au
2026-07-17 23:29:23
(2 days ago)
POST /xmlrpc.php HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 20:39:10
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.b ...
show more
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 16:39:06.549424 2026] [security2:error] [pid 1334800:tid 1334800] [client 179.189.78.232:54509] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||j3pr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "j3pr.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alqS6kYZrsSpzO2FSYJe4AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-17 20:10:43
(2 days ago)
[FriJul1722:10:38.1006012026][security2:error][pid2375930:tid2375953][client179.189.78.232:0]ModSecu ...
show more
[FriJul1722:10:38.1006012026][security2:error][pid2375930:tid2375953][client179.189.78.232:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"ilcartiglio.ch\"][uri\"/xmlrpc.php\"][unique_id\"alqMPpqsSLSvmjit94gxIQAAARQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 16:31:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.b ...
show more
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 12:31:41.472928 2026] [security2:error] [pid 8691:tid 8691] [client 179.189.78.232:57167] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coyotebytes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coyotebytes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alpY7Uj5-5K5cON1LIh19AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigwavedave
2026-07-17 16:30:35
(2 days ago)
Wordpress Attack
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-17 10:52:15
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:17:53
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.b ...
show more
(mod_security) mod_security (id:225170) triggered by 179.189.78.232 (179-189-78-232.cgnat.adyl.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:17:46.995365 2026] [security2:error] [pid 26279:tid 26279] [client 179.189.78.232:54636] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||shelbysmoak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "shelbysmoak.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aloBSiYcgFagjY9b68mePwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-16 22:30:11
(3 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH