Anonymous
2026-06-12 02:07:59
(6 hours ago)
Portscan: TCP/80 (4x), TCP/443 (2x)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-11 12:51:06
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 52.153.130.145 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.153.130.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:51:00.461483 2026] [security2:error] [pid 10309:tid 10404] [client 52.153.130.145:13132] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.munatseng.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.munatseng.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiqvNDNPiq4m0bA6yDed6wAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-11 12:44:02
(19 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 12:26:31
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 52.153.130.145 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.153.130.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:26:28.114629 2026] [security2:error] [pid 9132:tid 9132] [client 52.153.130.145:12317] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cnphilos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cnphilos.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiqpdANT-d0uxRPPB_96ogAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-11 11:47:22
(20 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
grassau.com
2026-06-11 11:43:28
(20 hours ago)
(wordpress) Failed wordpress login from 52.153.130.145 (US/United States/Wyoming/Cheyenne/-)
Brute-Force
Anonymous
2026-06-11 11:35:41
(20 hours ago)
52.153.130.145 - - [11/Jun/2026:13:35:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428
52.153.130.145 - ...
show more
52.153.130.145 - - [11/Jun/2026:13:35:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428
52.153.130.145 - - [11/Jun/2026:13:35:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428
...
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
nyt
2026-06-11 11:33:15
(20 hours ago)
XMLRPC Attack
Brute-Force
Web App Attack
๐ง๐ช
taivas.nl
2026-06-11 11:32:10
(20 hours ago)
Wordpress_xmlrpc_attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-11 11:25:16
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 52.153.130.145 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.153.130.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 07:25:08.547902 2026] [security2:error] [pid 13598:tid 13598] [client 52.153.130.145:12698] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||activethinkers.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "activethinkers.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiqbFJF7y89SFyjK_icz3QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-11 11:18:01
(21 hours ago)
trying wp-login.php/xmlrpc.php 31 times in 1 minutes
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-06-11 11:08:25
(21 hours ago)
[ThuJun1113:08:23.2818542026][security2:error][pid1929529:tid1929660][client52.153.130.145:0]ModSecu ...
show more
[ThuJun1113:08:23.2818542026][security2:error][pid1929529:tid1929660][client52.153.130.145:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"studio-portale.ch\"][uri\"/xmlrpc.php\"][unique_id\"aiqXJ0F2En6YKXQ0PIAiUwAAARE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-11 11:05:47
(21 hours ago)
Xmlrpc Caught (10)
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-11 10:56:04
(21 hours ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 10:46:19
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 52.153.130.145 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.153.130.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 06:46:14.832427 2026] [security2:error] [pid 7548:tid 7548] [client 52.153.130.145:12537] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.misogynyis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.misogynyis.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiqR9ioNH4mlYFhLydBIYwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack