๐ฌ๐ง
Smish
2026-03-16 09:00:39
(2 months ago)
HONEYPOT HIT --> Fail2ban time=1773651637 log=2026-03-16T09:00:37+00:00 ip=212.66.99.54 host=as21066 ...
show more
HONEYPOT HIT --> Fail2ban time=1773651637 log=2026-03-16T09:00:37+00:00 ip=212.66.99.54 host=as210667.net method=POST uri="/xmlrpc.php" status=404 ua="Mozilla/5.0 (Windows NT 6.2; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/93.0.0.0 Safari/537.36" ref="-" rid=57189806b1fa12e9acdc17af20c8878f
show less
Web App Attack
๐น๐ท
rtbh.com.tr
2026-03-14 20:12:03
(2 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฉ๐ช
LRob.fr
2026-03-13 09:30:09
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 17:15:59
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 212.66.99.54 (ip-099-054-dsl.customer.panservic ...
show more
(mod_security) mod_security (id:225170) triggered by 212.66.99.54 (ip-099-054-dsl.customer.panservice.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 13:15:52.578600 2026] [security2:error] [pid 27369:tid 27369] [client 212.66.99.54:59925] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arsenalfordemocracy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abL0yDPcfeHcUMROON91DQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
teamsecure
2026-03-12 12:02:09
(2 months ago)
Banned for trying to access xmlrpc
Web App Attack
๐ง๐ช
taivas.nl
2026-03-10 12:32:12
(2 months ago)
Wordpress_xmlrpc_attack
Bad Web Bot
๐ณ๐ฑ
Roderic
2026-03-09 10:46:35
(2 months ago)
(apache_scanners-2) Failed apache-scanners trigger with match [redacted])
Port Scan
๐ฉ๐ช
LRob.fr
2026-03-09 05:45:09
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 04:16:08
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 212.66.99.54 (ip-099-054-dsl.customer.panservic ...
show more
(mod_security) mod_security (id:225170) triggered by 212.66.99.54 (ip-099-054-dsl.customer.panservice.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 00:16:04.436428 2026] [security2:error] [pid 13230:tid 13339] [client 212.66.99.54:63753] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pathpointmarketplace.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pathpointmarketplace.click"] [uri "/wp-json/wp/v2/users"] [unique_id "aa5JhJoNTRxJuAj6nIkihgAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-08 18:11:21
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 212.66.99.54 (ip-099-054-dsl.customer.panservic ...
show more
(mod_security) mod_security (id:225170) triggered by 212.66.99.54 (ip-099-054-dsl.customer.panservice.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 14:11:16.544491 2026] [security2:error] [pid 7143:tid 7143] [client 212.66.99.54:61599] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||maffiniandbearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "maffiniandbearce.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aa27xKXJvk3D-wzamHUO2gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-03-08 14:32:00
(2 months ago)
(wordpress) Failed wordpress login from 212.66.99.54 (IT/Italy/Provincia di Latina/Latina/ip-099-054 ...
show more
(wordpress) Failed wordpress login from 212.66.99.54 (IT/Italy/Provincia di Latina/Latina/ip-099-054-dsl.customer.panservice.it)
show less
Brute-Force
๐บ๐ธ
integrantservices.com
2026-03-08 06:10:38
(2 months ago)
(wordpress) Failed wordpress login from 212.66.99.54 (IT/Italy/ip-099-054-dsl.customer.panservice.it ...
show more
(wordpress) Failed wordpress login from 212.66.99.54 (IT/Italy/ip-099-054-dsl.customer.panservice.it)
show less
Brute-Force
๐บ๐ธ
Jason Howell
2026-03-08 03:41:18
(2 months ago)
212.66.99.54 - - [07/Mar/2026:21:33:53 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3210 "-" "Mozilla/5.0 ...
show more
212.66.99.54 - - [07/Mar/2026:21:33:53 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3210 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/89.0.0.0 Safari/537.36"
212.66.99.54 - - [07/Mar/2026:21:38:23 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3210 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/11.0.0.0 Safari/537.36"
212.66.99.54 - - [07/Mar/2026:21:39:21 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3209 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/75.0.0.0 Safari/537.36"
212.66.99.54 - - [07/Mar/2026:21:40:19 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3209 "-" "Mozilla/5.0 (Windows NT 6.3; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/78.0.0.0 Safari/537.36"
212.66.99.54 - - [07/Mar/2026:21:41:17 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3210 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/89.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
myagent.site
2026-03-08 03:11:46
(2 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ธ๐ช
Per-Erik Runebert
2026-03-01 09:39:34
(3 months ago)
Malicious vulnerability hacking attacks
Hacking
Web App Attack