🇩🇪
FD-IX
2026-08-17 12:26:55
(3 weeks ago)
Brute-force login attack detected by WordPress firewall.
Brute-Force
Web App Attack
🇫🇷
tecnicorioja
2026-05-31 22:00:33
(3 months ago)
wp-login attack [31/May/2026:06:43:06
Brute-Force
Web App Attack
🇫🇮
tjs
2026-05-12 12:55:00
(3 months ago)
web attack, SQL injection attempt
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-05-08 21:02:10
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 93.177.119.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.119.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 17:02:04.569097 2026] [security2:error] [pid 17531:tid 17531] [client 93.177.119.96:38903] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||curryfirm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "curryfirm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "af5PTC_2EJg8Eg4VNKQK_wAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇿
ptlab
2026-04-27 12:46:34
(4 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
🇩🇪
Lino Project
2026-04-11 03:17:46
(4 months ago)
93.177.119.96 - - [11/Apr/2026:05:17:45 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3978 "-" "Mozilla/5.0 ...
show more
93.177.119.96 - - [11/Apr/2026:05:17:45 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3978 "-" "Mozilla/5.0 (Linux; Android 9; Mi 9 Lite) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.111 Mobile Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-03-29 08:47:59
(5 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:142.0) Gecko/20100101 Firefox/142.0 Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: POST Timestamp: 2026-03-29T08:47:59Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
🇩🇪
MusicLibrary
2026-03-22 20:38:08
(5 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-20 00:12:44
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 93.177.119.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.119.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:12:36.841156 2026] [security2:error] [pid 27895:tid 27895] [client 93.177.119.96:31153] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sinsky.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sinsky.net"] [uri "/wp-json/wp/v2/users"] [unique_id "abyQ9D9hEGs9jffQooR-VgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-03-19 12:40:25
(5 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: AppleWe ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: AppleWebKit/537.37 (KHTML, like Gecko111) Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: POST Timestamp: 2026-03-19T12:40:25Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
🇮🇩
BPS-StatisticsIndonesia
2026-03-17 10:59:58
(5 months ago)
XML RPC Scan Activities: "2026-03-17T17:59:58.446+07:00" "/xmlrpc.php" "93.177.119.96" "Mozilla/5.0 ...
show more
XML RPC Scan Activities: "2026-03-17T17:59:58.446+07:00" "/xmlrpc.php" "93.177.119.96" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:146.0) Gecko/20100101 Firefox/146.0"
show less
Web App Attack
Brute-Force
🇲🇾
Rizzy
2026-03-16 19:12:11
(5 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-03-16 09:41:24
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 93.177.119.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.119.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 05:41:20.301675 2026] [security2:error] [pid 16525:tid 16555] [client 93.177.119.96:19323] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kettlehill.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abfQQLXNJRd1KleGZs4dNgAAANQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
A000Z
2026-03-15 10:10:42
(5 months ago)
Fail2Ban: 93.177.119.96 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: AppleWebKi ...
show more
Fail2Ban: 93.177.119.96 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: AppleWebKit/531.31 (KHTML, like Gecko111)
show less
Bad Web Bot
🇮🇩
BPS-StatisticsIndonesia
2026-03-14 14:51:38
(5 months ago)
XML RPC Scan Activities: "2026-03-14T21:51:38.933+07:00" "/xmlrpc.php" "93.177.119.96" "Mozilla/5.0 ...
show more
XML RPC Scan Activities: "2026-03-14T21:51:38.933+07:00" "/xmlrpc.php" "93.177.119.96" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:143.0) Gecko/20100101 Firefox/143.0"
show less
Web App Attack
Brute-Force