🇺🇸
gui-ying233
2026-09-04 06:34:55
(5 days ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Bad Web Bot
🇩🇪
LRob
2026-08-06 14:01:58
(1 month ago)
CrowdSec: REPEAT OFFENDER (previously banned, came back) - distributed L7 HTTP flood on WordPress 'T ...
show more
CrowdSec: REPEAT OFFENDER (previously banned, came back) - distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/cat_ids~137,131,149/tag_ids~436,405,449,679,576,587/request_format~json/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36
show less
DDoS Attack
Web App Attack
🇩🇪
LRob
2026-08-03 13:45:31
(1 month ago)
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_forma ...
show more
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/time_limit~1763161200/cat_ids~549,194,381,172/tag_ids~436,677,608,615,405,633,482/request_format~json/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-06-10 05:38:53
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 01:38:48.568613 2026] [security2:error] [pid 14843:tid 14843] [client 37.40.91.221:57906] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.40.91.221 (+1 hits since last alert)|indiahouseportland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indiahouseportland.com"] [uri "/xmlrpc.php"] [unique_id "aij4aP_XdolhvMk5hmckGwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 05:02:04
(2 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
🇩🇪
rh24
2026-06-10 02:28:12
(2 months ago)
(wordpress) Failed wordpress login from 37.40.91.221 (OM/Oman/-): (CF_ENABLE)
Brute-Force
🇦🇺
screwlooseit.com.au
2026-06-10 02:27:34
(2 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
OM/Oman/-
Web App Attack
🇺🇸
TAY
2026-06-09 23:42:01
(2 months ago)
37.40.91.221 - - [10/Jun/2026:07:41:38 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack/12.0 ...
show more
37.40.91.221 - - [10/Jun/2026:07:41:38 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack/12.0; WordPress/6.1; http://site57848550.com"
37.40.91.221 - - [10/Jun/2026:07:41:47 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
37.40.91.221 - - [10/Jun/2026:07:42:00 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
...
show less
Brute-Force
Anonymous
2026-06-09 22:42:10
(2 months ago)
Attac
Brute-Force
🇺🇸
TPI-Abuse
2026-06-09 17:08:16
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 13:08:12.443987 2026] [security2:error] [pid 18229:tid 18229] [client 37.40.91.221:57896] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.40.91.221 (+1 hits since last alert)|birdlovesfish.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "birdlovesfish.com"] [uri "/xmlrpc.php"] [unique_id "aihIfPOhENSenKDxFasKNAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-19 11:35:23
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 07:35:17.012513 2026] [security2:error] [pid 887624:tid 887624] [client 37.40.91.221:3082] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nwarchitect.com|F|2"] [data ".dhakshiun.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nwarchitect.com"] [uri "/www.dhakshiun.com"] [unique_id "aeS99eP7Y0Jeda-rouVClAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-03 20:55:23
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 15:55:17.196405 2026] [security2:error] [pid 11249:tid 11249] [client 37.40.91.221:42227] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brushmileage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brushmileage.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aadKtckmZR_-Okx8EOQyKwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Tripwire
2026-03-03 16:15:56
(6 months ago)
Probing for Wordpress
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-03-03 15:34:47
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 37.40.91.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 10:34:09.356832 2026] [security2:error] [pid 27264:tid 27264] [client 37.40.91.221:41899] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rohanbyles.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rohanbyles.com.au"] [uri "/wp-json/wp/v2/users"] [unique_id "aab_carBEjTYoMP2jvkNcgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
i-turnradio.nl
2026-03-03 09:20:08
(6 months ago)
2026-03-03 10:20:07 (CET) ~ Blocked by abusescan risk assessment
Web App Attack