๐ซ๐ท
tecnicorioja
2026-04-22 22:00:45
(1 month ago)
POST /xmlrpc.php [22/Apr/2026:12:58:57
Web App Attack
Brute-Force
๐จ๐ฟ
ddw
2026-04-22 17:37:36
(1 month ago)
WordPress XMLRPC.PHP Access Attempt.
Hacking
Web App Attack
๐ญ๐ณ
soporte
2026-04-22 10:58:42
(1 month ago)
Probe for vulnerabilities. Path attempted: /xmlrpc.php
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-22 02:20:29
(1 month ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-21 21:14:26
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 95.173.221.20 (unn-95-173-221-20.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 95.173.221.20 (unn-95-173-221-20.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 17:14:22.661098 2026] [security2:error] [pid 4091747:tid 4091747] [client 95.173.221.20:45493] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artigelisim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artigelisim.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aefori-TbjPAg9Fl4EwEQAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-04-21 18:48:01
(1 month ago)
[TueApr2120:47:57.2948792026][security2:error][pid3025243:tid3025314][client95.173.221.20:0]ModSecur ...
show more
[TueApr2120:47:57.2948792026][security2:error][pid3025243:tid3025314][client95.173.221.20:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"vivereiltrentino.it\"][uri\"/xmlrpc.php\"][unique_id\"aefGXWR1Z2zCLsvvYp9yJQAAAEU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-21 14:14:28
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 95.173.221.20 (unn-95-173-221-20.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 95.173.221.20 (unn-95-173-221-20.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 10:14:21.837177 2026] [security2:error] [pid 1446117:tid 1446117] [client 95.173.221.20:40355] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ohiohca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ohiohca.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeeGPc66-7hOJD6wuExBjwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Reinhard
2026-04-21 12:48:53
(1 month ago)
Software package attack. /xmlrpc.php
Web App Attack
๐ฆ๐บ
Asimar
2026-04-21 09:38:03
(1 month ago)
(wordpress) Failed wordpress login from 95.173.221.20 (US/United States/unn-95-173-221-20.datapacket ...
show more
(wordpress) Failed wordpress login from 95.173.221.20 (US/United States/unn-95-173-221-20.datapacket.com): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-21 04:38:43
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 95.173.221.20 (unn-95-173-221-20.datapacket.com ...
show more
(mod_security) mod_security (id:225170) triggered by 95.173.221.20 (unn-95-173-221-20.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 00:38:35.639726 2026] [security2:error] [pid 2862002:tid 2862002] [client 95.173.221.20:37159] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||worshipconcert.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "worshipconcert.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeb_SzUHlewGOZ-Yu4MDtgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-21 02:06:03
(1 month ago)
Trying to access config files
Web App Attack
๐บ๐ธ
sailor
2026-04-20 19:47:00
(1 month ago)
Attempting to access WordPress potential exploit file: GET .../xmlrpc.php
Web App Attack
Hacking
๐ต๐ฑ
lns.bz
2026-04-20 18:28:17
(1 month ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-20 18:21:04
(1 month ago)
Unauthorized access to webpage admin
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-04-20 11:56:57
(1 month ago)
Try to access /xmlrpc.php
Web App Attack