Anonymous
2026-10-08 20:21:20
(1 hour ago)
Automated scanner probing RD Web Access login pages
Bad Web Bot
Web App Attack
๐ซ๐ท
claude CALVET
2026-08-19 18:44:12
(1 month ago)
gee-Joomla Admin : try to force the door...
Hacking
๐ฉ๐ช
4server
2026-07-31 05:42:02
(2 months ago)
193.203.8.129-security[07/31/2026:05:41:59-0000]\"GET\"FAILEDLOGINcpdavd:Couldnotfetchsystemhomedire ...
show more
193.203.8.129-security[07/31/2026:05:41:59-0000]\"GET\"FAILEDLOGINcpdavd:Couldnotfetchsystemhomedirectoryforsecurity155.212.38.106-security[07/31/2026:05:42:00-0000]\"GET\"FAILEDLOGINcpdavd:Couldnotfetchsystemhomedirectoryforsecurity193.203.8.65-security[07/31/2026:05:41:53-0000]\"GET\"FAILEDLOGINcpdavd:Couldnotfetchsystemhomedirectoryforsecurity185.168.30.128-security[07/31/2026:05:41:53-0000]\"GET\"FAILEDLOGINcpdavd:Couldnotfetchsystemhomedirectoryforsecurity122.8.45.253-security[07/31/2026:05:41:54-0000]\"GET\"FAILEDLOGINcpdavd:CouldnotfetchsystemhomedirectoryforsecurityIPAddressesBlocked:193.203.8.129\(US/UnitedStates/-\)155.212.38.106\(NL/TheNetherlands/-\)193.203.8.65\(US/UnitedStates/-\)
show less
Port Scan
Brute-Force
Web App Attack
๐ง๐ช
voormedia
2026-07-24 21:01:23
(2 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 02:27:05
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.168.30.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.168.30.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 22:26:57.230090 2026] [security2:error] [pid 196986:tid 196986] [client 185.168.30.128:20257] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||1healthplace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "1healthplace.com"] [uri "/wp-json/wp/v2/users"] [unique_id "almS8WeWDpF1_itmoGnd8gAAABQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-07-16 23:45:23
(2 months ago)
Web attack/Malicious activity detected
Web App Attack
Anonymous
2026-07-12 03:14:23
(2 months ago)
[redacted] 185.168.30.128 - - [12/Jul/2026:05:13:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" " ...
show more
[redacted] 185.168.30.128 - - [12/Jul/2026:05:13:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/11.0.31)"
[redacted] 185.168.30.128 - - [12/Jul/2026:05:13:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Apache-HttpClient/4.5.13 (Java/11.0.31)"
[redacted] 185.168.30.128 - - [12/Jul/2026:05:14:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/11.0.31)"
[redacted] 185.168.30.128 - - [12/Jul/2026:05:14:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Apache-HttpClient/4.5.13 (Java/11.0.31)"
[redacted] 185.168.30.128 - - [12/Jul/2026:05:14:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Apache-HttpClient/4.5.13 (Java/11.0.31)"
[redacted] 185.168.30.128 - - [12/Jul/2026:05:14:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 251 "-" "Apache-HttpClient/4.5.13 (Java/11.0.31)"
[redacted] 185.168.30.128 - - [12/Jul/2026:05:14:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 251 "-" "Apache-HttpClient/4.5.13 (J
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-04 02:26:00
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 185.168.30.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.168.30.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 22:25:57.179204 2026] [security2:error] [pid 21966:tid 21966] [client 185.168.30.128:53111] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||agenesis7.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "agenesis7.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afgDtQq6ifqBWzaMAdydFgAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NicoID
2026-05-02 00:13:25
(5 months ago)
185.168.30.128 - - [01/May/2026:12:07:40 -0600] "GET /wp-login.php HTTP/1.1" 200 4884 "https://www.g ...
show more
185.168.30.128 - - [01/May/2026:12:07:40 -0600] "GET /wp-login.php HTTP/1.1" 200 4884 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-29 00:24:55
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 185.168.30.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.168.30.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 20:24:49.206210 2026] [security2:error] [pid 4512:tid 4512] [client 185.168.30.128:48589] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||plumpen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "plumpen.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afFP0Q-LiaJlLt2pIUtJkAAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-28 19:06:00
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ง๐ช
voormedia
2026-04-28 03:22:54
(5 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 10:11:36
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 185.168.30.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 185.168.30.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 06:11:28.675116 2026] [security2:error] [pid 25112:tid 25112] [client 185.168.30.128:38379] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||slusarczyk.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "slusarczyk.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae82UMdDVEnEYKUUCMyz8AAAAB4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-04-21 02:47:13
(5 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-04-17 10:38:04
(5 months ago)
WordPress login attempt
Brute-Force