Anonymous
2026-07-24 19:24:04
(5 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
Lentini
2026-07-24 01:44:31
(23 hours ago)
visuitslagen.nl: malicious request:/xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 13:01:13
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.net.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 09:01:05.741231 2026] [security2:error] [pid 2471410:tid 2471410] [client 190.13.21.100:49451] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fishleadership.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fishleadership.org"] [uri "/wp-json/wp/v2/users"] [unique_id "amIQkR7VtjBMOxaa-HAyFQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 11:50:26
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-23 10:12:07
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-23 07:42:53
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.net.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 03:42:45.336436 2026] [security2:error] [pid 2370694:tid 2370694] [client 190.13.21.100:57501] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vanmeer.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vanmeer.info"] [uri "/wp-json/wp/v2/users"] [unique_id "amHF9Wj-i6uJWNshxlP2eQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-07-23 06:46:07
(1 day ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐ซ๐ฎ
stinpriza
2026-07-23 04:33:15
(1 day ago)
Web App Attack
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-23 03:00:49
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
CO/Colombia/190-13-21-100.telebucaramanga.net.co
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-23 02:51:56
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 190.13.21.100 (CO/Colombia/190-13-2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 190.13.21.100 (CO/Colombia/190-13-21-100.telebucaramanga.net.co): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 18:40:50
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.net.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 14:40:45.802360 2026] [security2:error] [pid 3265038:tid 3265038] [client 190.13.21.100:62179] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||designingdestinynow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "designingdestinynow.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amEOrWYiMqBXYVnN0OdY0AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 18:29:25
(2 days ago)
[redacted] 190.13.21.100 - - [22/Jul/2026:20:28:16 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Moz ...
show more
[redacted] 190.13.21.100 - - [22/Jul/2026:20:28:16 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Mozilla/5.0 (Windows NT 6.2; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
[redacted] 190.13.21.100 - - [22/Jul/2026:20:28:32 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/15.0.0.0 Safari/537.36"
[redacted] 190.13.21.100 - - [22/Jul/2026:20:28:49 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/11.0.0.0 Safari/537.36"
[redacted] 190.13.21.100 - - [22/Jul/2026:20:29:06 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Opera/60.0.0.0 Safari/537.36"
[redacted] 190.13.21.100 - - [22/Jul/2026:20:29:23 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 10:12:11
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.net.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:12:03.320554 2026] [security2:error] [pid 30622:tid 30691] [client 190.13.21.100:54118] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||visionforandfromchildren.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "visionforandfromchildren.org"] [uri "/wp-json/wp/v2/users"] [unique_id "al30c8qP9PPRCmfmJs3LUAAAAYY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-20 00:48:08
(5 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 14:01:19
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 190.13.21.100 (190-13-21-100.telebucaramanga.net.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 10:01:15.570094 2026] [security2:error] [pid 24714:tid 24714] [client 190.13.21.100:60200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geriterry.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geriterry.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aluHK2NvYTEvcVV-YbnyiwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack