๐บ๐ธ
Penny Packer
2026-08-18 15:46:25
(6 days ago)
Fail2Ban apache-tripwires
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-18 14:54:25
(6 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐จ๐ณ
Zhengka.net
2026-08-18 12:08:18
(6 days ago)
zhengka.net security honeypot hit; jail=zhengka.net_honeypot; ip=37.67.81.26
Port Scan
Web App Attack
Anonymous
2026-08-18 11:05:02
(6 days ago)
WEB attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-18 01:15:01
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 37.67.81.26 (26.81.67.37.rev.sfr.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 37.67.81.26 (26.81.67.37.rev.sfr.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:14:52.246451 2026] [security2:error] [pid 11923:tid 11923] [client 37.67.81.26:34933] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lysedzija.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoOyDCba8It7-tAp9Sg7mgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-17 22:44:50
(6 days ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
SSH
Web App Attack
Anonymous
2026-08-17 22:04:21
(6 days ago)
Web scanner: POST /xmlrpc.php
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-17 20:11:58
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 37.67.81.26 (26.81.67.37.rev.sfr.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 37.67.81.26 (26.81.67.37.rev.sfr.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 16:11:52.870193 2026] [security2:error] [pid 11065:tid 11065] [client 37.67.81.26:34551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greenmountainfeeds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greenmountainfeeds.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoNrCDfGC82G0FxiA4YUigAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-17 19:12:08
(6 days ago)
[MonAug1721:12:07.4209172026][security2:error][pid1739686:tid1739694][client37.67.81.26:0]ModSecurit ...
show more
[MonAug1721:12:07.4209172026][security2:error][pid1739686:tid1739694][client37.67.81.26:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"fondazionepetronillapontirone.ch\"][uri\"/xmlrpc.php\"][unique_id\"aoNdB_0XMkfX3QUheVhRIwAAAMU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-17 17:43:30
(6 days ago)
(wordpress) Failed wordpress login from 37.67.81.26 (FR/France/26.81.67.37.rev.sfr.net)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-17 16:14:53
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 37.67.81.26 (26.81.67.37.rev.sfr.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 37.67.81.26 (26.81.67.37.rev.sfr.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 12:14:48.229715 2026] [security2:error] [pid 11419:tid 11419] [client 37.67.81.26:34944] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||casapapayasanmiguel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "casapapayasanmiguel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoMzePJ4UgMwVxzH25DqigAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HERA - Operations
2026-08-17 15:09:39
(1 week ago)
bau-arge - searching for vulnerable scripts: xmlrpc.php 2026/08/17 17:09:39
Web App Attack
๐ฉ๐ช
LRob
2026-08-16 17:55:14
(1 week ago)
WordPress probing | req: /xmlrpc.php | UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKi ...
show more
WordPress probing | req: /xmlrpc.php | UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/15.0.0.0 Safari/537.36
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-16 12:41:06
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฌ๐ง
consul.to
2026-08-13 19:53:06
(1 week ago)
Web attack/malicious scanning detected
Web App Attack