๐บ๐ธ
TPI-Abuse
2025-12-16 13:19:20
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 49.145.43.164 (dsl.49.145.43.164.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 49.145.43.164 (dsl.49.145.43.164.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 16 08:19:16.773409 2025] [security2:error] [pid 29258:tid 29258] [client 49.145.43.164:47247] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "celebritybikinigossip.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aUFcVBrP_JDbUPGnOtu4JgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-12-15 16:05:50
(8 months ago)
Xmlrpc Caught (6)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-15 03:52:02
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 49.145.43.164 (dsl.49.145.43.164.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 49.145.43.164 (dsl.49.145.43.164.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 14 22:51:55.773870 2025] [security2:error] [pid 6703:tid 6703] [client 49.145.43.164:50130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mdsshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mdsshop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aT-F29mhzti4zWoy4bFMegAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-12-15 03:11:16
(8 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-14 00:41:07
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 49.145.43.164 (dsl.49.145.43.164.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 49.145.43.164 (dsl.49.145.43.164.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 19:41:01.421144 2025] [security2:error] [pid 645:tid 645] [client 49.145.43.164:50006] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cmcnow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cmcnow.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aT4HncAIEiq0TnbM-tz0tgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-13 01:49:26
(8 months ago)
[redacted] 49.145.43.164 - - [13/Dec/2025:02:49:07 +0100] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "M ...
show more
[redacted] 49.145.43.164 - - [13/Dec/2025:02:49:07 +0100] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
[redacted] 49.145.43.164 - - [13/Dec/2025:02:49:16 +0100] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
[redacted] 49.145.43.164 - - [13/Dec/2025:02:49:18 +0100] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
[redacted] 49.145.43.164 - - [13/Dec/2025:02:49:21 +0100] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
[redacted] 49.145.43.164 - - [13/Dec/2025:02:49:25 +0100] "POST /xmlrpc.php HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x
...
show less
Hacking
Web App Attack
Anonymous
2025-12-11 13:40:06
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
Jason Howell
2025-12-09 00:45:10
(8 months ago)
49.145.43.164 - - [08/Dec/2025:18:33:48 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3262 "-" "Mozilla/5.0 ...
show more
49.145.43.164 - - [08/Dec/2025:18:33:48 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3262 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
49.145.43.164 - - [08/Dec/2025:18:36:39 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3262 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
49.145.43.164 - - [08/Dec/2025:18:39:35 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3263 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
49.145.43.164 - - [08/Dec/2025:18:42:30 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3262 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
49.145.43.164 - - [08/Dec/2025:18:45:09 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3262 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome
...
show less
Web App Attack
Anonymous
2025-12-08 14:04:03
(8 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
octageeks.com
2025-12-08 05:07:38
(8 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 08:34:25
(8 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.43.164 (dsl.49.145.43.164.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.43.164 (dsl.49.145.43.164.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 03:34:17.984061 2025] [security2:error] [pid 9840:tid 9840] [client 49.145.43.164:49637] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.43.164 (+1 hits since last alert)|the-it-man.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "the-it-man.com"] [uri "/xmlrpc.php"] [unique_id "aTU8CdHfG4aJ3PF-KufBaQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฐ๐ท
Betatester
2024-12-07 07:46:00
(1 year ago)
xmlrpc.php attack attempt
Hacking
๐ฐ๐ท
Betatester
2024-12-06 22:46:00
(1 year ago)
xmlrpc.php POST request attempt, typical WordPress attack vector.
Web App Attack