๐ฎ๐น
Giorgio Cupelli
2026-09-24 10:13:53
(5 days ago)
Port Scan
๐ง๐ช
voormedia
2025-11-12 13:24:17
(10 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 09:41:40
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; ...
show more
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 04:41:33.999992 2025] [security2:error] [pid 21039:tid 21086] [client 62.3.3.8:2505] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wegelin.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wegelin.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ8QTa_axuCXABgpJ8RMNgAAAc8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 07:05:24
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; ...
show more
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 02:05:20.824111 2025] [security2:error] [pid 26480:tid 26480] [client 62.3.3.8:36691] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wendeeholtcamp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wendeeholtcamp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ7rsKw7A3qTLX0FTAUK8gAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2025-11-07 09:12:12
(10 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ง๐พ
lns.bz
2025-11-06 21:04:30
(10 months ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
๐ฎ๐น
LTM
2025-11-06 07:20:01
(10 months ago)
IP/Port Scan
Port Scan
Brute-Force
๐ฉ๐ช
FeG Deutschland
2025-11-05 19:27:21
(10 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
octageeks.com
2025-11-05 05:06:29
(10 months ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
Anonymous
2025-11-04 07:34:33
(10 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET /wp-json/wp/v2/users HTTP/1.1 ...
show more
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET /wp-json/wp/v2/users HTTP/1.1, GET /wp-login.php HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-04 06:24:22
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; ...
show more
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 04 01:24:18.183589 2025] [security2:error] [pid 31654:tid 31654] [client 62.3.3.8:18653] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||peazy.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "peazy.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aQmcEsfZtEgc86WBErwURQAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-04 04:50:22
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; ...
show more
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 03 23:50:15.068220 2025] [security2:error] [pid 25300:tid 25300] [client 62.3.3.8:58573] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQmGB3Fg3zRUZZKfdIkVxQAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-04 03:43:07
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; ...
show more
(mod_security) mod_security (id:225170) triggered by 62.3.3.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 03 22:43:02.280424 2025] [security2:error] [pid 17439:tid 17439] [client 62.3.3.8:12645] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webjemm.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webjemm.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aQl2RnhAjbP_emPXjpfYswAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-03 23:50:08
(10 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฉ๐ช
LRob
2025-11-03 15:37:12
(10 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack