๐ซ๐ท
tecnicorioja
2026-09-22 22:01:25
(20 hours ago)
POST /xmlrpc.php [22/Sep/2026:09:02:38
Web App Attack
Brute-Force
Anonymous
2026-09-22 18:35:14
(23 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
Anonymous
2026-09-22 13:07:11
(1 day ago)
2026-09-22T13:07:10.177910+00:00 instance-20260804-1025 wordpress(netal.co)[987951]: XML-RPC authent ...
show more
2026-09-22T13:07:10.177910+00:00 instance-20260804-1025 wordpress(netal.co)[987951]: XML-RPC authentication attempt for unknown user udtuores from 34.194.78.239
...
show less
Web App Attack
Anonymous
2026-09-22 02:47:03
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
QT
2026-09-22 01:48:24
(1 day ago)
Unauthorised WordPress admin login attempted at 2026-09-22 11:48:16 +1000
Web App Attack
๐ฌ๐ง
BRHosting
2026-09-21 21:39:02
(1 day ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-09-21 07:46:03
(2 days ago)
Wordfence waf block on pameganslaw
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 09:16:26
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 05:16:22.533192 2026] [security2:error] [pid 11903:tid 11903] [client 34.194.78.239:44592] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||renjunews.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "renjunews.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq-kZraSkBwmxy7w9yKRAQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 00:36:12
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 20:36:07.642877 2026] [security2:error] [pid 29805:tid 29805] [client 34.194.78.239:50312] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.incrp.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.incrp.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq8qd-icyEMlWXQLDt804AAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-09-19 23:55:37
(3 days ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐ฉ๐ช
maxpower
2026-09-19 23:10:27
(3 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 34.194.78.239 (US/United States/ec2-34-194-78- ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 34.194.78.239 (US/United States/ec2-34-194-78-239.compute-1.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.194.78.239 - - [20/Sep/2026:01:10:23 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12146 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0" "-" host=blogdigiovanni.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 18:50:12
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:50:08.981093 2026] [security2:error] [pid 7920:tid 7920] [client 34.194.78.239:6622] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||josephshv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "josephshv.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7ZYC6jMXMdVgS3inAGHwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 09:53:11
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 05:53:07.881874 2026] [security2:error] [pid 17692:tid 17692] [client 34.194.78.239:10846] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ixd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ixd.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5bg0sfPZ3A4oq6waaZrAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 09:31:24
(5 days ago)
34.194.78.239 - - [18/Sep/2026:11:31:18 +0200] "GET /?author=2 HTTP/1.1" 404 23112 "-" "Mozilla/5.0 ...
show more
34.194.78.239 - - [18/Sep/2026:11:31:18 +0200] "GET /?author=2 HTTP/1.1" 404 23112 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0"
34.194.78.239 - - [18/Sep/2026:11:31:18 +0200] "GET /?author=2 HTTP/1.1" 404 5980 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0"
34.194.78.239 - - [18/Sep/2026:11:31:18 +0200] "GET /?author=3 HTTP/1.1" 404 23112 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0"
34.194.78.239 - - [18/Sep/2026:11:31:18 +0200] "GET /?author=3 HTTP/1.1" 404 5980 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:49.0) Gecko/20100101 Firefox/49.0"
34.194.78.239 - - [18/Sep/2026:11:31:18 +0200] "GET /?author=4 HTTP/1.1" 404 23112 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0"
34.194.78.239 - - [18/Sep/2026:11:31:18 +0200] "GET /?author=4 HTTP/1.1" 404 5980 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:54.0) Gecko/20100101 Firefox/5
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 02:14:51
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 34.194.78.239 (ec2-34-194-78-239.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 22:14:43.519881 2026] [security2:error] [pid 10197:tid 10197] [client 34.194.78.239:34983] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.superlamb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.superlamb.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqyek7zU2rKvc8L3wgiydQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack