๐บ๐ธ
EvilTurkey
2026-09-15 12:23:35
(1 day ago)
Web app attack against financial institution website.
Web App Attack
Hacking
๐ฉ๐ฐ
ScamAware
2026-09-14 21:59:55
(2 days ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot / scanner behavior). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Bad Web Bot
๐ท๐ด
iulianh
2026-09-14 21:58:40
(2 days ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-14 21:56:18
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:56:12.365438 2026] [security2:error] [pid 3615:tid 3615] [client 20.2.197.149:1508] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||greenmountainfeeds.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "greenmountainfeeds.com"] [uri "/"] [unique_id "aqhtfJOdm9drGENpg77g2wAAAA8"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-09-14 21:53:25
(2 days ago)
(XMLRPC) WP XMLRPC Attack 20.2.197.149 (HK/Hong Kong/-/Hong Kong/-/[AS8075 Microsoft Corporation]): ...
show more
(XMLRPC) WP XMLRPC Attack 20.2.197.149 (HK/Hong Kong/-/Hong Kong/-/[AS8075 Microsoft Corporation]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.2.197.149 - - [15/Sep/2026:00:52:48 +0300] "GET /xmlrpc.php HTTP/1.1" 503 7310 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.1.15"
show less
Port Scan
๐ฉ๐ช
big-cloud.nl
2026-09-14 21:49:43
(2 days ago)
Try to access /xmlrpc.php
Web App Attack
๐ฉ๐ช
4server
2026-09-14 21:39:10
(2 days ago)
[MonSep1423:39:06.1642662026][security2:error][pid2356724:tid2356806][client20.2.197.149:0]ModSecuri ...
show more
[MonSep1423:39:06.1642662026][security2:error][pid2356724:tid2356806][client20.2.197.149:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"orabonastudio.it\"][uri\"/xmlrpc.php\"][unique_id\"aqhpejFWyxzNueAjCHmW2wAAAEg\"]\,referer:https://www.bing.com/
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 21:36:23
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:36:17.570514 2026] [security2:error] [pid 20530:tid 20530] [client 20.2.197.149:1555] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||landjudging.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "landjudging.com"] [uri "/"] [unique_id "aqho0bC9dy8KTHcVpHkWiwAAAAg"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 21:20:08
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:20:01.376169 2026] [security2:error] [pid 474:tid 474] [client 20.2.197.149:1224] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||autodiscover.powdercoatovens.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "autodiscover.powdercoatovens.net"] [uri "/xmlrpc.php"] [unique_id "aqhlAcwsvd9CQ0Y8ZoUTjQAAAAQ"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-14 21:17:48
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 21:04:03
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:03:57.424231 2026] [security2:error] [pid 24480:tid 24480] [client 20.2.197.149:1438] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||autodiscover.meganmurph.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "autodiscover.meganmurph.com"] [uri "/xmlrpc.php"] [unique_id "aqhhPWCpAyr9dcVaC31zMAAAAAA"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-14 20:44:05
(2 days ago)
[MonSep1422:43:58.6532192026][security2:error][pid1999222:tid1999236][client20.2.197.149:0]ModSecuri ...
show more
[MonSep1422:43:58.6532192026][security2:error][pid1999222:tid1999236][client20.2.197.149:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"614\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"rs-solution.ch\"][uri\"/xmlrpc.php\"][unique_id\"aqhcjgp7kvvckdSEnlgNwAAAAUk\"]\,referer:https://www.google.fr/search\?q=wordpress
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 20:40:16
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 16:40:11.719189 2026] [security2:error] [pid 5406:tid 5406] [client 20.2.197.149:1236] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||autodiscover.lancehancock.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "autodiscover.lancehancock.com"] [uri "/xmlrpc.php"] [unique_id "aqhbq4dSTIgcEhzlbtQTGAAAAAM"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
Saec
2026-09-14 20:40:02
(2 days ago)
Jarvis auto-ban: CF honeypot path /xmlrpc.php (1ร on saec.me)
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 20:24:08
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 20.2.197.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 16:24:00.740871 2026] [security2:error] [pid 28525:tid 28525] [client 20.2.197.149:1545] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||greentirerecycling.mapleleaf-marketing.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "greentirerecycling.mapleleaf-marketing.com"] [uri "/"] [unique_id "aqhX4IGYrbaM_N6u4zzDRgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack