๐ณ๐ฑ
maxxsense
2025-12-29 18:30:38
(9 months ago)
(wordpress) Failed wordpress login from 72.167.65.237 (US/United States/237.65.167.72.host.secureser ...
show more
(wordpress) Failed wordpress login from 72.167.65.237 (US/United States/237.65.167.72.host.secureserver.net)
show less
Brute-Force
๐ฉ๐ช
jasperedv.de
2025-12-29 18:26:36
(9 months ago)
Apache Login - Brutforcing
Brute-Force
Web App Attack
๐ฆ๐บ
weblite
2025-12-29 18:14:48
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2025-12-29 18:06:37
(9 months ago)
Authentication failure for eboney
Hacking
๐ง๐ช
taivas.nl
2025-12-29 18:02:11
(9 months ago)
Wordpress_xmlrpc_attack
Bad Web Bot
๐บ๐ธ
myagent.site
2025-12-29 14:44:45
(9 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฒ๐น
Malta
2025-12-29 14:32:30
(9 months ago)
72.167.65.237 - - [29/Dec/2025:15:32:30 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
72.167.65.237 - - [29/Dec/2025:15:32:30 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; Trident/7.0; Touch; MDDCJS; rv:11.0) like Gecko"
Brute-force password attempt
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2025-12-29 14:09:51
(9 months ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-12 03:04:36
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 22:04:31.278074 2025] [security2:error] [pid 17504:tid 17504] [client 72.167.65.237:51102] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dwightbrown.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dwightbrown.com"] [uri "/wp-json/Wp/v2/users"] [unique_id "aTuGP8UFj21ppkBuv-jpNQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 16:57:02
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 11:56:57.719642 2025] [security2:error] [pid 4967:tid 4967] [client 72.167.65.237:59888] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.modalguitarist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.modalguitarist.com"] [uri "/wp-json/wp/v2/users.json"] [unique_id "aTr32WOr-krbzp0x23n2RgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 15:42:07
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 10:42:01.481112 2025] [security2:error] [pid 14401:tid 14401] [client 72.167.65.237:63406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.casaniagara.com.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.casaniagara.com.mx"] [uri "/wp-json/Wp/v2/users"] [unique_id "aTrmSav4zVc3B-rXWDxevwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 13:10:47
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 08:10:43.565318 2025] [security2:error] [pid 28941:tid 28941] [client 72.167.65.237:20976] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.owldreamllc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.owldreamllc.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "aTrC00fRwz2C80v0MKfIFwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 07:42:09
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 02:42:02.264419 2025] [security2:error] [pid 20178:tid 20178] [client 72.167.65.237:11808] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fusteriafontane.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fusteriafontane.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "aTp1yoQm1moz-ZBb2kdBHgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2025-12-11 07:07:29
(9 months ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-11 04:18:16
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 72.167.65.237 (237.65.167.72.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 23:18:13.662846 2025] [security2:error] [pid 32688:tid 32688] [client 72.167.65.237:30036] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||natickvillagerentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "natickvillagerentals.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTpGBcRkvOTJd5PRGfqPqAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack