🇸🇪
peterh
2026-09-04 11:04:00
(11 hours ago)
77.81.237.91 - - [04/Sep/2026:11:39:20 +0200] "POST /xmlrpc.php HTTP/1.1"
Web App Attack
Hacking
🇸🇪
SkyDancer
2026-09-04 09:42:16
(12 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇨🇭
4server
2026-09-04 02:47:45
(19 hours ago)
[FriSep0404:47:41.4833902026][security2:error][pid2896216:tid2896816][client77.81.237.91:0]ModSecuri ...
show more
[FriSep0404:47:41.4833902026][security2:error][pid2896216:tid2896816][client77.81.237.91:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"xmlrpc\\\\\\\\.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/03_asl_dos.conf\"][line\"65\"][id\"392331\"][rev\"3\"][msg\"Atomicorp.comWAFRules:xmlrpcDOSattack\"][severity\"CRITICAL\"][hostname\"ticinosystem.ch\"][uri\"/xmlrpc.php\"][unique_id\"apoxTTecPW2shKPUpZMtowAAAMI\"]
show less
Hacking
Web App Attack
🇩🇪
big-cloud.nl
2026-09-03 04:18:29
(1 day ago)
Try to access /xmlrpc.php
Web App Attack
🇮🇹
VHosting
2026-09-02 22:25:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇴
jad-abuse
2026-09-02 14:26:27
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
🇫🇷
SpaceHost-Server
2026-06-22 22:34:10
(2 months ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-21 09:14:37
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.a ...
show more
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 05:14:28.526809 2026] [security2:error] [pid 21931:tid 21931] [client 77.81.237.91:42408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.batesstrategygroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.batesstrategygroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajerdHKpZ8I9KH3zkGOtPQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-19 20:01:20
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.a ...
show more
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 16:01:13.437184 2026] [security2:error] [pid 14358:tid 14358] [client 77.81.237.91:57934] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kaylamaclaincounseling.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kaylamaclaincounseling.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWgCaUI5SCCNpkYuTte-gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
SpaceHost-Server
2026-06-18 22:33:55
(2 months ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-18 14:49:54
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.a ...
show more
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 10:49:48.531615 2026] [security2:error] [pid 14860:tid 14860] [client 77.81.237.91:53840] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dceabronwilliams.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dceabronwilliams.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajQFjDhHHThqKJ-rHGyCwwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-18 06:32:36
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.a ...
show more
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 02:32:29.517839 2026] [security2:error] [pid 11405:tid 11405] [client 77.81.237.91:45746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fatcaverecords.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fatcaverecords.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajOQ_cd-4DgCvlK2uANnzwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-16 23:22:17
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.a ...
show more
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 19:22:13.124519 2026] [security2:error] [pid 4641:tid 4641] [client 77.81.237.91:36058] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.margroberts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.margroberts.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajHapcWWznqUmzX9uNCC5wAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-06-16 07:21:29
(2 months ago)
(modsecurity) srv101 ModSecurity 77.81.237.91 (IT/Italy/host91-237-81-77.serverdedicati.aruba.it): 1 ...
show more
(modsecurity) srv101 ModSecurity 77.81.237.91 (IT/Italy/host91-237-81-77.serverdedicati.aruba.it): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-06-15 22:37:10
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.a ...
show more
(mod_security) mod_security (id:225170) triggered by 77.81.237.91 (host91-237-81-77.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 18:37:05.864361 2026] [security2:error] [pid 25086:tid 25086] [client 77.81.237.91:50002] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.investorsfundingusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.investorsfundingusa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajB-kR18BjP5ArKU-D4ODAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack