๐ฉ๐ช
stinpriza
2026-03-28 08:10:31
(5 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
juguemosalacarioca.com
2026-03-28 06:56:31
(5 months ago)
Multiple HTTP calls attempting to GET resources using common API calls or formats on port 8080
Web App Attack
Anonymous
2026-03-28 06:13:32
(5 months ago)
(wordpress) Failed wordpress login from 5.93.9.74 (IT/Italy/mob-5-93-9-74.net.vodafone.it)
Brute-Force
Anonymous
2026-03-28 03:26:02
(5 months ago)
Bot / scanning and/or hacking attempts: GET /xmlrpc.php HTTP/1.1, POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฌ๐ง
andypiper
2026-03-28 02:02:41
(5 months ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2026-03-28 01:52:12
(5 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐บ๐ธ
Void Vendor
2026-03-28 01:09:31
(5 months ago)
VoidTrap [15,21]: [offense #1 โ 30 minutes] Honeypot: /xmlrpc.php | ip: 5.93.9.74 | loc: Rome, Lazio ...
show more
VoidTrap [15,21]: [offense #1 โ 30 minutes] Honeypot: /xmlrpc.php | ip: 5.93.9.74 | loc: Rome, Lazio, IT, AS30722 Fastweb SpA | path: /xmlrpc.php | ua: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/5
show less
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-03-26 12:25:50
(5 months ago)
๐ก Port scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 11:22:49
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 5.93.9.74 (mob-5-93-9-74.net.vodafone.it): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 5.93.9.74 (mob-5-93-9-74.net.vodafone.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 07:22:41.659580 2026] [security2:error] [pid 31684:tid 31684] [client 5.93.9.74:52101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||redlitephotos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "redlitephotos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acUXAbv34JF4CcIF0uJGSwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
neo72
2026-03-26 06:13:40
(5 months ago)
Detected malicious activity - bulk block
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 06:13:08
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 5.93.9.74 (mob-5-93-9-74.net.vodafone.it): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 5.93.9.74 (mob-5-93-9-74.net.vodafone.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 02:12:59.684947 2026] [security2:error] [pid 26977:tid 26977] [client 5.93.9.74:52340] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naturalacu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naturalacu.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acTOaymm6LyFDejse49c3AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Mario Silber
2026-03-26 00:16:19
(5 months ago)
(wordpress) Failed wordpress login from 5.93.9.74 (IT/Italy/mob-5-93-9-74.net.vodafone.it)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-25 19:10:41
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 5.93.9.74 (mob-5-93-9-74.net.vodafone.it): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 5.93.9.74 (mob-5-93-9-74.net.vodafone.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 15:10:33.710176 2026] [security2:error] [pid 15500:tid 15500] [client 5.93.9.74:50253] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosurehomeservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosurehomeservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acQzKbb1rHjB4ZEjIGtSQgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 18:51:31
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 5.93.9.74 (mob-5-93-9-74.net.vodafone.it): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 5.93.9.74 (mob-5-93-9-74.net.vodafone.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 14:51:27.112174 2026] [security2:error] [pid 11959:tid 11962] [client 5.93.9.74:63079] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosurepressurewashing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosurepressurewashing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acQur30kdhrloJH6V3fTwQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-03-25 18:18:44
(5 months ago)
Honeypot triggered: /xmlrpc.php on ifebridge.com. User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64 ...
show more
Honeypot triggered: /xmlrpc.php on ifebridge.com. User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/68.0.0.0 Safari/537.36. Method: POST
show less
Web App Attack