๐ช๐ธ
librebit
2026-01-14 17:00:51
(6 months ago)
Brute force
Brute-Force
Anonymous
2026-01-13 14:52:05
(6 months ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-01-11 19:31:44
(6 months ago)
Failed Wordpress login
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
Kenshin869
2026-01-11 10:31:33
(6 months ago)
Wordpress unauthorized access attempt
Brute-Force
๐ช๐ธ
masterguru
2026-01-11 09:50:34
(6 months ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack
๐บ๐ธ
factor1
2026-01-11 09:43:03
(6 months ago)
Fail2ban at saturn Reports Abuse.
Brute-Force
Web App Attack
๐ฉ๐ช
John Chrys.
2026-01-08 23:01:54
(6 months ago)
92.205.135.133 - - [09/Jan/2026:01:01:52 +0200] "POST /xmlrpc.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 ...
show more
92.205.135.133 - - [09/Jan/2026:01:01:52 +0200] "POST /xmlrpc.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; apetito Gruppe; rv:11.0) like Gecko"
92.205.135.133 - - [09/Jan/2026:01:01:52 +0200] "POST /xmlrpc.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; apetito Gruppe; rv:11.0) like Gecko"
92.205.135.133 - - [09/Jan/2026:01:01:53 +0200] "POST /xmlrpc.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; apetito Gruppe; rv:11.0) like Gecko"
92.205.135.133 - - [09/Jan/2026:01:01:53 +0200] "POST /xmlrpc.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; apetito Gruppe; rv:11.0) like Gecko"
92.205.135.133 - - [09/Jan/2026:01:01:53 +0200] "POST /xmlrpc.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; apetito Gruppe; rv:11.0) like Gecko"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-01-08 16:45:43
(6 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-01-08 09:50:02
(6 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-01-07 14:39:20
(6 months ago)
92.205.135.133 - - [07/Jan/2026:15:39:19 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintos ...
show more
92.205.135.133 - - [07/Jan/2026:15:39:19 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.1 Safari/605.1.15"
show less
VPN IP
Hacking
Web App Attack
๐ณ๐ฑ
Rey
2026-01-07 10:42:02
(6 months ago)
WordPress xmlrpc.php attack [5dssr1rg]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-05 04:21:07
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 92.205.135.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 92.205.135.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 23:21:00.413477 2026] [security2:error] [pid 23172:tid 23172] [client 92.205.135.133:63168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lockdownclaim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lockdownclaim.com"] [uri "/wp-json/Wp/v2/users"] [unique_id "aVs8LMWHGcx7M_aQedrbKAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-04 12:02:27
(6 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-03 21:57:10
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 92.205.135.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 92.205.135.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 16:57:06.482896 2026] [security2:error] [pid 21248:tid 21248] [client 92.205.135.133:54560] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.beirutbazar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.beirutbazar.com"] [uri "/wp-json/Wp/v2/users"] [unique_id "aVmQsgrwb_n2RszP13bqYgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-03 18:40:45
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 92.205.135.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 92.205.135.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 13:40:41.321582 2026] [security2:error] [pid 14712:tid 14712] [client 92.205.135.133:28010] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.truthsabouthealthcare.com"] [uri "/wp-json/Wp/v2/users"] [unique_id "aVliqU6s2Tbqy33TEeDgegAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack