🇪🇸
librebit
2026-08-30 09:56:41
(10 hours ago)
Brute force
Brute-Force
🇺🇸
TPI-Abuse
2026-06-17 12:18:22
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 83.142.55.142 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 83.142.55.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 08:18:15.599675 2026] [security2:error] [pid 23068:tid 23068] [client 83.142.55.142:33421] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aquascapes.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aquascapes.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajKQh4pOjJ1cy374elrWbgAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Major Hostility
2026-06-07 15:50:38
(2 months ago)
"POST /xmlrpc.php HTTP/1.1" 403
"GET /wp-login.php HTTP/1.1" 404
"GET /wp-login.php HTTP/1.1" 404
"G ...
show more
"POST /xmlrpc.php HTTP/1.1" 403
"GET /wp-login.php HTTP/1.1" 404
"GET /wp-login.php HTTP/1.1" 404
"GET /wp-admin.php HTTP/1.1" 404
"GET /wp-json/wp/v2/users HTTP/1.1" 404
"POST /xmlrpc.php HTTP/1.1" 403
"GET /wp-login.php HTTP/1.1" 404
"GET /wp-login.php HTTP/1.1" 404
"GET /wp-admin.php HTTP/1.1" 404
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-06-06 06:10:11
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 83.142.55.142 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 83.142.55.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 02:10:04.170575 2026] [security2:error] [pid 860:tid 860] [client 83.142.55.142:55845] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||insidepublications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "insidepublications.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiO5vLcD56EKnS0lfdpp9wAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
JustMeHere
2026-05-30 14:35:41
(3 months ago)
[Sat May 30 10:35:36.861952 2026] [security2:error] [pid 135016:tid 135059] [client 83.142.55.142:27 ...
show more
[Sat May 30 10:35:36.861952 2026] [security2:error] [pid 135016:tid 135059] [client 83.142.55.142:27807] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/xmlrpc.php"] [unique_id "ahr1uIX5jHK3V3YM6IqtjQAAAA8"]
...
show less
Web App Attack
Anonymous
2026-05-26 15:10:18
(3 months ago)
SQL injection, multiple attempts.
SQL Injection
🇺🇸
TPI-Abuse
2026-05-25 12:50:22
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 83.142.55.142 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 83.142.55.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 08:50:15.226327 2026] [security2:error] [pid 21761:tid 21761] [client 83.142.55.142:42537] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||normteslaa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "normteslaa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahRFhyqTn2WM6oiLaOp1ugAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Jason Howell
2026-05-11 21:10:31
(3 months ago)
83.142.55.142 - - [11/May/2026:21:10:24 +0000] "POST /xmlrpc.php HTTP/1.1" 200 2718 "-" "Apache-Http ...
show more
83.142.55.142 - - [11/May/2026:21:10:24 +0000] "POST /xmlrpc.php HTTP/1.1" 200 2718 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
83.142.55.142 - - [11/May/2026:21:10:25 +0000] "POST /xmlrpc.php HTTP/1.1" 200 2793 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
83.142.55.142 - - [11/May/2026:21:10:26 +0000] "GET /wp-login.php HTTP/1.1" 200 3994 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
83.142.55.142 - - [11/May/2026:21:10:30 +0000] "POST /xmlrpc.php HTTP/1.1" 200 2719 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
83.142.55.142 - - [11/May/2026:21:10:30 +0000] "POST /xmlrpc.php HTTP/1.1" 200 2794 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
...
show less
Web App Attack
🇩🇪
MusicLibrary
2026-04-16 17:41:15
(4 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
🇮🇪
Coolnagour
2026-04-14 13:01:35
(4 months ago)
http-probing: /xmlrpc.php
Web App Attack
Anonymous
2026-04-13 03:04:55
(4 months ago)
"POST /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
🇩🇪
MusicLibrary
2026-04-02 16:20:32
(4 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
🇩🇪
MusicLibrary
2026-03-28 18:20:05
(5 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
🇩🇪
MusicLibrary
2026-03-24 09:32:20
(5 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
🇮🇩
BPS-StatisticsIndonesia
2026-03-22 20:03:13
(5 months ago)
XML RPC Scan Activities: "2026-03-23T03:03:13.631+07:00" "/xmlrpc.php" "83.142.55.142" "Mozilla/5.0 ...
show more
XML RPC Scan Activities: "2026-03-23T03:03:13.631+07:00" "/xmlrpc.php" "83.142.55.142" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:140.0) Gecko/20100101 Firefox/140.0"
show less
Web App Attack
Brute-Force