๐ฉ๐ช
grassau.com
2026-08-27 18:40:02
(1 day ago)
(wordpress) Failed wordpress login from 78.28.52.75 (PL/Poland/Pomerania/Chojnice/ch5275.petrus.pl)
Brute-Force
๐บ๐ธ
Dave Hansen
2026-08-27 17:02:59
(1 day ago)
(wordpress) Failed wordpress login from 78.28.52.75 (PL/Poland/ch5275.petrus.pl)
Brute-Force
๐ณ๐ฑ
Site.eu
2026-08-26 18:59:55
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฑ
Site.eu
2026-08-24 14:40:31
(4 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฆ๐บ
screwlooseit.com.au
2026-08-23 16:43:19
(5 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PL/Poland/ch5275.petrus.pl
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 20:06:59
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 78.28.52.75 (ch5275.petrus.pl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 78.28.52.75 (ch5275.petrus.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:06:55.507720 2026] [security2:error] [pid 7200:tid 7200] [client 78.28.52.75:54114] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||expresstires.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "expresstires.us"] [uri "/wp-json/wp/v2/users"] [unique_id "aooBXxBeSgmSsasxgp1uNwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-08-22 14:20:50
(6 days ago)
(XMLRPC) WP XMLRPC Attack 78.28.52.75 (PL/Poland/Pomerania/Chojnice/-/[AS44914 PETRUS-CH-AS]): 1 in ...
show more
(XMLRPC) WP XMLRPC Attack 78.28.52.75 (PL/Poland/Pomerania/Chojnice/-/[AS44914 PETRUS-CH-AS]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 78.28.52.75 - - [22/Aug/2026:17:12:42 +0300] "POST /xmlrpc.php HTTP/1.1" 404 57248 "-" "Mozilla/5.0 (Windows NT 6.2; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36"
show less
Port Scan
๐ฉ๐ช
bsoft.de
2026-08-19 14:17:50
(1 week ago)
78.28.52.75 - - [19/Aug/2026:16:16:44 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 404 148 "-" "Mozill ...
show more
78.28.52.75 - - [19/Aug/2026:16:16:44 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 404 148 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"
78.28.52.75 - - [19/Aug/2026:16:17:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/61.0.0.0 Safari/537.36"
78.28.52.75 - - [19/Aug/2026:16:17:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Opera/69.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
bsoft.de
2026-08-18 16:51:44
(1 week ago)
78.28.52.75 - - [18/Aug/2026:18:48:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (M ...
show more
78.28.52.75 - - [18/Aug/2026:18:48:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Opera/60.0.0.0 Safari/537.36"
78.28.52.75 - - [18/Aug/2026:18:51:15 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 404 148 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"
78.28.52.75 - - [18/Aug/2026:18:51:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/77.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 14:44:48
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 78.28.52.75 (ch5275.petrus.pl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 78.28.52.75 (ch5275.petrus.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 10:44:41.525084 2026] [security2:error] [pid 21564:tid 21564] [client 78.28.52.75:51936] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gerrytolentino.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gerrytolentino.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aoRv2dbvYaxn7zeqLPJmBQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 11:00:20
(1 week ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ณ๐ด
jad-abuse
2026-08-18 08:49:55
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 19:05:13
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 78.28.52.75 (ch5275.petrus.pl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 78.28.52.75 (ch5275.petrus.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 15:05:07.494400 2026] [security2:error] [pid 21458:tid 21458] [client 78.28.52.75:65478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bickleton.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aoIJ499qaUOn6PhKuP4tCwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-16 14:06:45
(1 week ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
mnsf
2026-08-14 14:05:41
(2 weeks ago)
Xmlrpc Caught (7)
Brute-Force
Web App Attack