๐ท๐บ
DZBOT
2026-07-22 14:44:16
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ญ
4server
2026-07-22 00:48:22
(1 day ago)
[WedJul2202:48:15.7423022026][security2:error][pid117286:tid117305][client42.119.59.28:0]ModSecurity ...
show more
[WedJul2202:48:15.7423022026][security2:error][pid117286:tid117305][client42.119.59.28:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"cacciatorichiasso.ch\"][uri\"/xmlrpc.php\"][unique_id\"amATT3TUSYoUkM-CFBlYvwAAAUQ\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-07-21 00:26:40
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 11:45:28
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 42.119.59.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 42.119.59.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:45:14.708734 2026] [security2:error] [pid 14858:tid 14858] [client 42.119.59.28:62447] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||agrollum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "agrollum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al4KSp1RNSu4RexyGLUWugAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
origrata
2026-07-20 04:59:40
(3 days ago)
[OGWAF] xmlrpc_bruteforce attack blocked | severity: critical | POST /xmlrpc.php | UA: Mozilla/5.0 ( ...
show more
[OGWAF] xmlrpc_bruteforce attack blocked | severity: critical | POST /xmlrpc.php | UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/80.0.0 | payload: <?xml version="1.0"?><methodCall><methodName>metaWeblog.newPost</methodName><params><param><value><string>1</string></value></param><param><value><string>99232</string></value></param><param><value><s
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 20:23:14
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 42.119.59.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 42.119.59.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 16:22:59.539460 2026] [security2:error] [pid 25110:tid 25110] [client 42.119.59.28:51130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dianamead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dianamead.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al0yI03AR3th30HoZ_ghrgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-19 15:28:46
(4 days ago)
(xmlrpc) Failed xmlrpc access from 42.119.59.28 (VN/Vietnam/-): 5 in the last 3600 secs (0-122)
Hacking
๐จ๐ญ
4server
2026-07-18 13:01:26
(5 days ago)
[SatJul1815:01:17.7076092026][security2:error][pid736404:tid736645][client42.119.59.28:0]ModSecurity ...
show more
[SatJul1815:01:17.7076092026][security2:error][pid736404:tid736645][client42.119.59.28:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"eutecne.ch\"][uri\"/xmlrpc.php\"][unique_id\"alt5HUOT5p0Mr4MklfYe6QAAARc\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 12:49:07
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 42.119.59.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 42.119.59.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 08:48:54.333190 2026] [security2:error] [pid 1008849:tid 1008854] [client 42.119.59.28:50987] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||worldecom.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "worldecom.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aloktgQZShlrivF6ugoIaAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-17 10:09:41
(6 days ago)
(wordpress) Failed wordpress login from 42.119.59.28 (VN/Vietnam/Hanoi/Hanoi/-/[redacted]): (CF_ENA ...
show more
(wordpress) Failed wordpress login from 42.119.59.28 (VN/Vietnam/Hanoi/Hanoi/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐ฎ๐ฉ
Burayot
2026-07-17 10:09:41
(6 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 42.119.59.28 (VN/Vietnam/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 42.119.59.28 (VN/Vietnam/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 00:44:28
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 42.119.59.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 42.119.59.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 20:44:13.362564 2026] [security2:error] [pid 32977:tid 32977] [client 42.119.59.28:53415] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||deborahbein.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "deborahbein.com"] [uri "/wp-json/wp/v2/users"] [unique_id "all63QBuII8TQRlIvmHXAAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-16 12:27:46
(1 week ago)
42.119.59.28 - - [16/Jul/2026:08:26:22 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "Mozilla/5.0 ...
show more
42.119.59.28 - - [16/Jul/2026:08:26:22 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/13.0.0.0 Safari/537.36"
42.119.59.28 - - [16/Jul/2026:08:26:52 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/68.0.0.0 Safari/537.36"
42.119.59.28 - - [16/Jul/2026:08:27:19 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36"
42.119.59.28 - - [16/Jul/2026:08:27:33 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36"
42.119.59.28 - - [16/Jul/2026:08:27:45 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/80.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-15 18:48:18
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
ctidrv
2026-07-14 07:17:42
(1 week ago)
Honeypot detection. Threat score: 45/100. Collector: honeypot. | Request: GET /xmlrpc.php | UA: Mozi ...
show more
Honeypot detection. Threat score: 45/100. Collector: honeypot. | Request: GET /xmlrpc.php | UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/87.0.0.0 Safari/537.36 | Reasons: suspicious_path, no_sec_fetch, no_cookies, no_accept_encoding
show less
Bad Web Bot