๐บ๐ธ
raymarron.com
2026-08-22 22:25:33
(6 hours ago)
POST /xmlrpc.php
Web App Attack
Anonymous
2026-08-22 11:46:03
(17 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-22 11:42:01
(17 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-22 00:41:36
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 20:41:24.623492 2026] [security2:error] [pid 32639:tid 32639] [client 45.114.151.77:65460] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||instalatoribucuresti.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "instalatoribucuresti.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aojwNNrSYX4t87hZM5xaggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
securejdprop
2026-08-21 17:28:01
(1 day ago)
This IP was detected by CrowdSec triggering custom/vpatch-xmlrpc-abuse.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-21 17:12:43
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:12:30.523226 2026] [security2:error] [pid 13678:tid 13678] [client 45.114.151.77:59636] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bosdkbook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bosdkbook.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoiG_pnIPgWp7h4akxGSYAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-08-20 19:03:32
(2 days ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-08-18 23:19:46
(4 days ago)
[WedAug1901:19:32.5828232026][security2:error][pid1664124:tid1664186][client45.114.151.77:0]ModSecur ...
show more
[WedAug1901:19:32.5828232026][security2:error][pid1664124:tid1664186][client45.114.151.77:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"serban.ch\"][uri\"/xmlrpc.php\"][unique_id\"aoTohHD9_B3VcXpm8d0cEQAAAE4\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฆ๐บ
Bay13
2026-08-18 20:15:27
(4 days ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 20:37:57
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 16:37:47.484339 2026] [security2:error] [pid 19959:tid 19959] [client 45.114.151.77:62419] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hawaiireservations.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hawaiireservations.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoNxG5nQfKZhYPgW9CToFAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 00:39:23
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 20:39:10.959908 2026] [security2:error] [pid 14681:tid 14681] [client 45.114.151.77:60312] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ohanameetup.party|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ohanameetup.party"] [uri "/wp-json/wp/v2/users"] [unique_id "an-1LkK5udAPnlcWZqauQwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 02:18:58
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.114.151.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 22:18:46.404736 2026] [security2:error] [pid 1882240:tid 1882257] [client 45.114.151.77:56169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||managementlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "managementlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "an57Bl_d8j0oSV6aE_nDdAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-14 01:18:39
(1 week ago)
[redacted] 45.114.151.77 - - [14/Aug/2026:03:17:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "M ...
show more
[redacted] 45.114.151.77 - - [14/Aug/2026:03:17:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.0.0 Safari/537.36"
[redacted] 45.114.151.77 - - [14/Aug/2026:03:17:48 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Opera/74.0.0.0 Safari/537.36"
[redacted] 45.114.151.77 - - [14/Aug/2026:03:17:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/76.0.0.0 Safari/537.36"
[redacted] 45.114.151.77 - - [14/Aug/2026:03:18:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Linux; Android 10; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/14.0.0.0 Safari/537.36"
[redacted] 45.114.151.77 - - [14/Aug/2026:03:18:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
enpepet
2026-08-13 11:11:07
(1 week ago)
GENERAL: parametres: [url:xmlrpc=] UA:Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.3 ...
show more
GENERAL: parametres: [url:xmlrpc=] UA:Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/78.0.0.0 Safari/537.36 URL:/xmlrpc.php
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐ณ๐ฟ
Tripwire
2026-08-10 17:43:58
(1 week ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack