Anonymous
2026-07-24 04:38:04
(3 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-07-24 01:38:16
(6 hours ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Mozilla/5.0 (X11; Ubunt ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
show less
Brute-Force
Web App Attack
๐บ๐ธ
k3rn3l109
2026-07-23 20:26:43
(11 hours ago)
Sentinel honeypot: cf-waf-auto hit on sentinelmdm.com UA=Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm ...
show more
Sentinel honeypot: cf-waf-auto hit on sentinelmdm.com UA=Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/13.0.0.0 Safari/537.36
show less
Hacking
๐จ๐ฆ
polycoda
2026-07-23 12:13:06
(20 hours ago)
๐ Wordpress login brute force attempt
Hacking
Web App Attack
๐ฉ๐ช
konseptit
2026-07-23 04:03:27
(1 day ago)
(wordpress) Failed wordpress login from 41.220.47.89 (MZ/Mozambique/cust89-47.netcabo.co.mz)
Brute-Force
๐ฉ๐ช
4server
2026-07-22 17:34:32
(1 day ago)
[WedJul2219:34:30.1808832026][security2:error][pid718645:tid718679][client41.220.47.89:0]ModSecurity ...
show more
[WedJul2219:34:30.1808832026][security2:error][pid718645:tid718679][client41.220.47.89:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"cbri.ch\"][uri\"/xmlrpc.php\"][unique_id\"amD_JiD3UAIq8BYDS-3qyQAAARc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 12:19:48
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.220.47.89 (cust89-47.netcabo.co.mz): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 41.220.47.89 (cust89-47.netcabo.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 08:19:44.628282 2026] [security2:error] [pid 1154945:tid 1154945] [client 41.220.47.89:6116] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||smilingorc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "smilingorc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amC1YICOgWjmjA8xwJDxbgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-07-22 06:54:22
(2 days ago)
Known malicious PHP file or CMS probe
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-22 02:32:16
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-22 01:57:02
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 41.220.47.89 (cust89-47.netcabo.co.mz): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 41.220.47.89 (cust89-47.netcabo.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 21:56:54.231331 2026] [security2:error] [pid 349702:tid 349725] [client 41.220.47.89:24159] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coasterdvdsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coasterdvdsonline.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amAjZqyONLVn9Pff0BfpBAAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-21 13:23:23
(2 days ago)
Try to access /xmlrpc.php
Web App Attack
๐จ๐ฆ
zXero
2026-07-21 12:22:19
(2 days ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
๐บ๐ธ
Penny Packer
2026-07-20 22:56:32
(3 days ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-20 19:56:03
(3 days ago)
(wordpress) Failed wordpress login from 41.220.47.89 (MZ/Mozambique/cust89-47.netcabo.co.mz)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 10:54:27
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 41.220.47.89 (cust89-47.netcabo.co.mz): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 41.220.47.89 (cust89-47.netcabo.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:54:19.488053 2026] [security2:error] [pid 26006:tid 26006] [client 41.220.47.89:54247] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zacharypowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zacharypowers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al3-Wz33cVOFw8I137-aNQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack