Anonymous
2026-07-29 07:00:00
(1 day ago)
Automated Apache web application probing in selected 24h window; attempts=233, unique_paths=1, error ...
show more
Automated Apache web application probing in selected 24h window; attempts=233, unique_paths=1, error_responses=233; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=352; exact paths: /xmlrpc.php
Web App Attack
Anonymous
2026-07-29 01:58:54
(1 day ago)
(wordpress) Failed wordpress login from 87.116.181.147 (RS/Serbia/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-28 22:25:02
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 18:24:55.264476 2026] [security2:error] [pid 123906:tid 123906] [client 87.116.181.147:15881] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.116.181.147 (+1 hits since last alert)|jdsqrd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jdsqrd.com"] [uri "/xmlrpc.php"] [unique_id "amksN8sC0Ti9IfBq3fpV1gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-28 21:36:03
(2 days ago)
Wordfence waf block on kcuar
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-28 15:05:37
(2 days ago)
87.116.181.147 - - [28/Jul/2026:11:04:00 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress. ...
show more
87.116.181.147 - - [28/Jul/2026:11:04:00 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
87.116.181.147 - - [28/Jul/2026:11:04:21 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
87.116.181.147 - - [28/Jul/2026:11:04:42 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
87.116.181.147 - - [28/Jul/2026:11:05:25 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
87.116.181.147 - - [28/Jul/2026:11:05:35 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
Anonymous
2026-07-28 07:51:47
(2 days ago)
(wordpress) Failed wordpress login from 87.116.181.147 (RS/Serbia/Belgrade/Belgrade/-/[redacted])
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-28 06:20:17
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 02:20:11.800711 2026] [security2:error] [pid 1857959:tid 1857959] [client 87.116.181.147:40157] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.116.181.147 (+1 hits since last alert)|eileensharaga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eileensharaga.com"] [uri "/xmlrpc.php"] [unique_id "amhKGzHl24wo9SYdLetYdwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 05:50:51
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:50:45.228247 2026] [security2:error] [pid 995369:tid 995369] [client 87.116.181.147:40088] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.116.181.147 (+1 hits since last alert)|swinjury.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "swinjury.co"] [uri "/xmlrpc.php"] [unique_id "amhDNYUk59sCzQOLbFvBTwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 05:18:55
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:18:48.520864 2026] [security2:error] [pid 1722117:tid 1722117] [client 87.116.181.147:16074] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.116.181.147 (+1 hits since last alert)|prcomputersolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "prcomputersolutions.com"] [uri "/xmlrpc.php"] [unique_id "amg7uMMvxZtp55ADwbDC9QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 02:03:24
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 22:03:18.022376 2026] [security2:error] [pid 176527:tid 176527] [client 87.116.181.147:40006] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.116.181.147 (+1 hits since last alert)|zost.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zost.net"] [uri "/xmlrpc.php"] [unique_id "amgN5kttZ_o15o_9z5JgsgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-27 18:58:47
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 18:30:55
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 87.116.181.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:30:46.019598 2026] [security2:error] [pid 3250807:tid 3251161] [client 87.116.181.147:16015] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.116.181.147 (+1 hits since last alert)|piazza9.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "piazza9.com"] [uri "/xmlrpc.php"] [unique_id "amej1rbVIP3bi2WED38w_gAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-27 17:18:47
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 28
Exploited Host
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-27 16:55:42
(3 days ago)
(wordpress) Failed wordpress login from 87.116.181.147 (RS/Serbia/-)
Brute-Force