🇧🇪
taivas.nl
2026-09-13 09:32:11
(9 hours ago)
Bad_requests
Bad Web Bot
🇷🇴
iulianh
2026-09-13 09:11:02
(9 hours ago)
80,443
Brute-Force
SSH
🇺🇸
oralunal
2026-09-13 09:07:40
(9 hours ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
🇩🇪
wpadm3
2026-09-13 09:04:17
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇧🇪
cmbplf
2026-09-13 09:03:48
(9 hours ago)
19.172 requests in 1 hour (3mos1w6d)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 09:03:08
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.109.139.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 192.109.139.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:03:03.509126 2026] [security2:error] [pid 9286:tid 9286] [client 192.109.139.3:65517] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jillbauman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jillbauman.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqZmx2qzVhNAgE155jXNaQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-09-13 08:56:03
(9 hours ago)
Wordfence waf block on madesimpleskincare
Web App Attack
Anonymous
2026-09-13 08:37:56
(10 hours ago)
[redacted] 192.109.139.3 - - [13/Sep/2026:10:37:48 +0200] "POST //xmlrpc.php HTTP/1.1" 200 403 "-" " ...
show more
[redacted] 192.109.139.3 - - [13/Sep/2026:10:37:48 +0200] "POST //xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 192.109.139.3 - - [13/Sep/2026:10:37:48 +0200] "POST //xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 192.109.139.3 - - [13/Sep/2026:10:37:49 +0200] "POST //xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 192.109.139.3 - - [13/Sep/2026:10:37:50 +0200] "POST //xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 192.109.139.3 - - [13/Sep/2026:10:37:51 +0200] "POST //xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT
...
show less
Hacking
Web App Attack
🇩🇪
LRob
2026-09-13 08:34:21
(10 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: // (+1 more) | query: author=1 (+1 more) | 2026-09-13 08:34 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-13 08:34:02
(10 hours ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1
Hacking
Web App Attack
🇩🇪
maxpower
2026-09-13 08:32:13
(10 hours ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 192.109.139.3 (US/United States/-): 3 in the l ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 192.109.139.3 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/09/13 10:32:09 [error] 2643749#2643749: *340566 access forbidden by rule, client: 192.109.139.3, server: centrolarca.eu, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "centrolarca.eu"
2026/09/13 10:32:09 [error] 2643749#2643749: *340566 access forbidden by rule, client: 192.109.139.3, server: centrolarca.eu, request: "GET //?author=1 HTTP/2.0", host: "centrolarca.eu"
2026/09/13 10:32:09 [error] 2643749#2643749: *340566 access forbidden by rule, client: 192.109.139.3, server: centrolarca.eu, request: "GET //?author=2 HTTP/2.0", host: "centrolarca.eu"
show less
Port Scan
🇺🇸
integrantservices.com
2026-09-13 08:26:50
(10 hours ago)
(PERMBLOCK) 192.109.139.3 (US/United States/-) has had more than 4 temp blocks
Hacking
🇳🇿
Antinson
2026-09-13 08:22:37
(10 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 08:19:01
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 192.109.139.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 192.109.139.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:18:54.133654 2026] [security2:error] [pid 18577:tid 18577] [client 192.109.139.3:59522] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jwhitelive.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jwhitelive.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqZcbnfzpz5RcBnWlPxTlgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Lino Project
2026-09-13 08:14:28
(10 hours ago)
192.109.139.3 - - [13/Sep/2026:10:14:25 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 403 628 "-" "Mozilla/ ...
show more
192.109.139.3 - - [13/Sep/2026:10:14:25 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 403 628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack