Anonymous
2026-02-24 07:08:00
(7 months ago)
(wordpress) Failed wordpress login from 74.0.42.64 (NL/Netherlands/-)
Brute-Force
๐ง๐ช
cmbplf
2026-02-24 06:25:14
(7 months ago)
932 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2026-02-24 04:42:01
(7 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 20:01:24
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 74.0.42.64 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 74.0.42.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 15:01:18.350520 2026] [security2:error] [pid 2055:tid 2055] [client 74.0.42.64:45203] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||innolympics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "innolympics.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZyyDtLuXekSl5MOrxhQ1QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 19:41:19
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 74.0.42.64 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 74.0.42.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 14:41:13.017023 2026] [security2:error] [pid 12378:tid 12378] [client 74.0.42.64:20704] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grexicon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grexicon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZytWZRcgz8aN4hgd0x84gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-02-23 19:36:09
(7 months ago)
(wordpress) Failed wordpress login from 74.0.42.64 (NL/Netherlands/-): (CF_ENABLE)
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-02-23 12:53:43
(7 months ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 08:44:54
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 74.0.42.64 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 74.0.42.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 03:44:46.829409 2026] [security2:error] [pid 8461:tid 8461] [client 74.0.42.64:60062] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prostar.industries"] [uri "/wp-json/wp/v2/users"] [unique_id "aZwTfjjtwfRZcphzpMG0TQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-02-23 08:23:02
(7 months ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer
... [wa01]
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-02-23 07:32:11
(7 months ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer
... [wa02]
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-02-22 23:30:09
(7 months ago)
(xmlrpc) Apache: Failed xmlrpc access from 74.0.42.64 (NL/The Netherlands/-): 10 in the last 3600 se ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 74.0.42.64 (NL/The Netherlands/-): 10 in the last 3600 secs (0-180)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-22 20:54:44
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 74.0.42.64 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 74.0.42.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 15:54:39.839244 2026] [security2:error] [pid 400:tid 400] [client 74.0.42.64:54175] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||studioyau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "studioyau.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZttDy23aAFowAt3JTueOgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-22 19:05:14
(7 months ago)
Xmlrpc Caught (6)
Brute-Force
Web App Attack
๐ฎ๐ฉ
Burayot
2026-02-22 18:20:45
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 74.0.42.64 (NL/Netherlands/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 74.0.42.64 (NL/Netherlands/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-02-22 11:16:02
(7 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack