Anonymous
2026-06-11 13:40:20
(1 day ago)
2026-06-11T15:40:18.842218+02:00 zanati wp(www.serviceflow.co.za)[1039860]: Blocked user enumeration ...
show more
2026-06-11T15:40:18.842218+02:00 zanati wp(www.serviceflow.co.za)[1039860]: Blocked user enumeration attempt from 196.196.53.5
...
show less
Web App Attack
๐บ๐ธ
factor1
2026-06-11 11:23:54
(2 days ago)
Fail2ban at saturn Reports Abuse.
Brute-Force
Web App Attack
๐ฉ๐ช
pscriptos
2026-06-11 11:20:24
(2 days ago)
{"ClientAddr":"196.196.53.5:54949","ClientHost":"196.196.53.5","ClientPort":"54949","ClientUsername" ...
show more
{"ClientAddr":"196.196.53.5:54949","ClientHost":"196.196.53.5","ClientPort":"54949","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":147154663,"OriginContentSize":418,"OriginDuration":144362253,"OriginStatus":403,"Overhead":2792410,"RequestAddr":"www.cleveradmin.de","RequestContentSize":197,"RequestCount":1824854,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-06-11T13:20:23.137974249+02:00","StartUTC":"2026-06-11T11:20:23.137974249Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-06-11T13:20:23+02:00"}
{"ClientAddr":"196.196.53.5:36215","ClientHost":"196.196.53.5","ClientPort":"36215"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
yvoictra
2026-06-11 10:13:14
(2 days ago)
196.196.53.5 - - [11/Jun/2026:12:13:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 222 "-" "Mozilla/5.0 ( ...
show more
196.196.53.5 - - [11/Jun/2026:12:13:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 222 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
196.196.53.5 - - [11/Jun/2026:12:13:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 222 "-" "Mozilla/5.0 (Linux; Android 14; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36"
196.196.53.5 - - [11/Jun/2026:12:13:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 222 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
196.196.53.5 - - [11/Jun/2026:12:13:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 222 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
196.196.53.5 - - [11/Jun/2026:12:13:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 222 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1"
...
show less
Brute-Force
Web App Attack
๐ธ๐ฌ
pusathosting.com
2026-06-11 08:50:26
(2 days ago)
24ds22 bruteforce
Brute-Force
Web App Attack
Anonymous
2026-06-11 03:50:14
(2 days ago)
196.196.53.5 - - [11/Jun/2026:05:50:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 ( ...
show more
196.196.53.5 - - [11/Jun/2026:05:50:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 (Linux; Android 14; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36"
196.196.53.5 - - [11/Jun/2026:05:50:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (Linux; Android 14; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36"
196.196.53.5 - - [11/Jun/2026:05:50:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_2_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15"
196.196.53.5 - - [11/Jun/2026:05:50:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 420 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_2_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15"
196.196.53.5 - - [11/Jun/2026:05:50:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
tmiland
2026-06-10 23:35:32
(2 days ago)
(wordpress_xmlrpc) WordPress XMLPRC Attack 196.196.53.5 (LV/Latvia/-): 3 in the last 3600 secs; IP: ...
show more
(wordpress_xmlrpc) WordPress XMLPRC Attack 196.196.53.5 (LV/Latvia/-): 3 in the last 3600 secs; IP: 196.196.53.5; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 196.196.53.5 - - [11/Jun/2026:01:35:04 +0200] "POST /xmlrpc.php HTTP/1.1" 499 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 196.196.53.5 - - [11/Jun/2026:01:35:15 +0200] "POST /xmlrpc.php HTTP/1.1" 499 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1" 196.196.53.5 - - [11/Jun/2026:01:35:25 +0200] "POST /xmlrpc.php HTTP/1.1" 499 0 "-" "Mozilla/5.0 (Linux; Android 14; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36"
show less
Brute-Force
Anonymous
2026-06-08 01:46:17
(5 days ago)
Failed Wordpress Logins
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-07 16:08:42
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 08:33:38
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 196.196.53.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 196.196.53.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 04:33:32.890444 2026] [security2:error] [pid 24180:tid 24180] [client 196.196.53.5:29781] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pinetreedistrict.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pinetreedistrict.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aiUs3DCAUFRKtN_wNsoX3QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-07 05:15:07
(6 days ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ธ๐ฌ
mypatricks
2026-06-06 21:27:05
(6 days ago)
196.196.53.5 | Port: 12460 | DNS: 196.196.53.12 2026-06-07T05:27:04+08:00 Europe/Riga | Web App Atta ...
show more
196.196.53.5 | Port: 12460 | DNS: 196.196.53.12 2026-06-07T05:27:04+08:00 Europe/Riga | Web App Attack | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 HTTP/1.1 443 GET | URL: /?author=131 | Ref: - | Country: LV/Latvia/+02:00 IP City: Riga Windows a07a7fb17ca1e4e3-RIX/Riga, Latvia 35 hits/23 secs Browser 1
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-05 12:38:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 196.196.53.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 196.196.53.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 08:38:29.996293 2026] [security2:error] [pid 11661:tid 11661] [client 196.196.53.5:54213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.214"] [uri "/wp-config.php"] [unique_id "aiLDRXfHIrr-JhMi2in4FQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 11:31:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 196.196.53.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 196.196.53.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 07:31:18.677638 2026] [security2:error] [pid 8464:tid 8474] [client 196.196.53.5:24015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baronlongford.com"] [uri "/.env.development"] [unique_id "aiKzhnTbtB7KLG9Wh43YcwAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-06-05 07:28:40
(1 week ago)
Blocked by UFW (TCP on 51413)
Source port: 45194
TTL: 49
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 51413)
Source port: 45194
TTL: 49
Packet length: 60
TOS: 0x08
This report (for 196.196.53.5) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan