๐ฎ๐น
VHosting
2026-01-11 21:30:02
(8 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2026-01-11 21:01:25
(8 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
Anonymous
2025-12-21 21:26:11
(9 months ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
myagent.site
2025-12-20 08:01:43
(9 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ณ๐ฑ
BlueWire Hosting
2025-09-02 04:10:40
(1 year ago)
Probing for application vulnerabilities
Brute-Force
Web App Attack
๐บ๐ธ
xmission.com
2025-09-02 00:53:20
(1 year ago)
2001:1810:4181:120:0:4:42af:2c35 - - [01/Sep/2025:18:53:20 -0600] "POST /xmlrpc.php HTTP/1.1" 200 41 ...
show more
2001:1810:4181:120:0:4:42af:2c35 - - [01/Sep/2025:18:53:20 -0600] "POST /xmlrpc.php HTTP/1.1" 200 413 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:85.0) Gecko/20100101 Firefox/91.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 23:38:59
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4181:120:0:4:42af:2c35 (web193c40.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4181:120:0:4:42af:2c35 (web193c40.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 19:38:53.178310 2025] [security2:error] [pid 8052:tid 8052] [client 2001:1810:4181:120:0:4:42af:2c35:48424] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jazziientertainment.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jazziientertainment.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aLYujSvo5y6zl1k5yreXGQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 22:24:02
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4181:120:0:4:42af:2c35 (web193c40.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4181:120:0:4:42af:2c35 (web193c40.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 18:23:57.593875 2025] [security2:error] [pid 13827:tid 13827] [client 2001:1810:4181:120:0:4:42af:2c35:40838] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webuychesterfieldhouses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webuychesterfieldhouses.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aLYc_d6svlmxwgu3USsRrgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 20:45:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4181:120:0:4:42af:2c35 (web193c40.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4181:120:0:4:42af:2c35 (web193c40.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 16:45:52.170481 2025] [security2:error] [pid 1413973:tid 1413992] [client 2001:1810:4181:120:0:4:42af:2c35:41566] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gabegabel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gabegabel.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aLYGANlRoYdGEAfA9-cGcQAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 19:57:22
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2001:1810:4181:120:0:4:42af:2c35 (web193c40.car ...
show more
(mod_security) mod_security (id:225170) triggered by 2001:1810:4181:120:0:4:42af:2c35 (web193c40.carrierzone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 15:57:16.873776 2025] [security2:error] [pid 32016:tid 32016] [client 2001:1810:4181:120:0:4:42af:2c35:56276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ecushopper.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ecushopper.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aLX6nEovbW94hfv5H2DJ3gAAAAE"], referer: http://ecushopper.com///wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-09-01 19:35:20
(1 year ago)
Multiple attempts to attack Wordpress XMLRPC detected: access blocked.
Web App Attack
๐ฎ๐น
mgarofano80
2025-09-01 19:23:53
(1 year ago)
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2025-09-01 19:20:42
(1 year ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐บ๐ธ
myagent.site
2025-09-01 16:53:13
(1 year ago)
Blocked user enumeration attempt
Hacking
๐จ๐ญ
teamsecure
2025-06-16 03:39:36
(1 year ago)
Banned for trying to access wp-login
Web App Attack