๐ช๐ธ
SweetHoneyPress
2026-06-17 21:30:18
(6 hours ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=786510 | UA: Mozilla/5.0 (Windows NT 6.3; x64) Ap ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=786510 | UA: Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
๐ช๐ธ
SweetHoneyPress
2026-06-17 21:15:15
(7 hours ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=786465 | UA: Mozilla/5.0 (Linux; Android 10; x86) ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=786465 | UA: Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/85.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
๐ช๐ธ
SweetHoneyPress
2026-06-17 20:59:55
(7 hours ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=786249 | UA: Mozilla/5.0 (Linux; Android 10; x64) ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=786249 | UA: Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/75.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
๐ช๐ธ
SweetHoneyPress
2026-06-17 20:44:53
(7 hours ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=786214 | UA: Mozilla/5.0 (Windows NT 6.3; arm64) ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=786214 | UA: Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/99.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
Anonymous
2026-06-17 17:05:44
(11 hours ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (15/60 min)'; Requests=15
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-17 09:49:11
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 95.246.82.11 (host-95-246-82-11.retail.telecomi ...
show more
(mod_security) mod_security (id:225170) triggered by 95.246.82.11 (host-95-246-82-11.retail.telecomitalia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 05:49:03.566653 2026] [security2:error] [pid 28944:tid 28944] [client 95.246.82.11:63487] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||constructionloansfunding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "constructionloansfunding.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajJtj2vA76VU2roocmZYQAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-16 00:21:10
(2 days ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐ฉ๐ช
stinpriza
2026-06-15 23:24:16
(2 days ago)
Web App Attack
Web App Attack
๐จ๐ญ
4server
2026-06-13 16:37:09
(4 days ago)
[SatJun1318:37:06.3758712026][security2:error][pid2047370:tid2047400][client95.246.82.11:0]ModSecuri ...
show more
[SatJun1318:37:06.3758712026][security2:error][pid2047370:tid2047400][client95.246.82.11:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"4server.biz\"][uri\"/xmlrpc.php\"][unique_id\"ai2HMqq_aF3PTM6Wk3e4igAAAVc\"]
show less
Hacking
Web App Attack
Anonymous
2026-06-12 10:07:51
(5 days ago)
[redacted] 95.246.82.11 - - [12/Jun/2026:12:07:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mo ...
show more
[redacted] 95.246.82.11 - - [12/Jun/2026:12:07:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.2; x64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/91.0.0.0 Safari/537.36"
[redacted] 95.246.82.11 - - [12/Jun/2026:12:07:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.3; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/13.0.0.0 Safari/537.36"
[redacted] 95.246.82.11 - - [12/Jun/2026:12:07:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36"
[redacted] 95.246.82.11 - - [12/Jun/2026:12:07:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/93.0.0.0 Safari/537.36"
[redacted] 95.246.82.11 - - [12/Jun/2026:12:07:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.3; x86) AppleWebKit/537.36 (KHTML, like Gec
...
show less
Hacking
Web App Attack
Anonymous
2026-06-11 23:00:45
(6 days ago)
[redacted] 95.246.82.11 - - [12/Jun/2026:00:59:35 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mo ...
show more
[redacted] 95.246.82.11 - - [12/Jun/2026:00:59:35 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/82.0.0.0 Safari/537.36"
[redacted] 95.246.82.11 - - [12/Jun/2026:00:59:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.3; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.0.0 Safari/537.36"
[redacted] 95.246.82.11 - - [12/Jun/2026:01:00:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
[redacted] 95.246.82.11 - - [12/Jun/2026:01:00:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36"
[redacted] 95.246.82.11 - - [12/Jun/2026:01:00:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, li
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 15:45:32
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.246.82.11 (host-95-246-82-11.retail.telecomi ...
show more
(mod_security) mod_security (id:225170) triggered by 95.246.82.11 (host-95-246-82-11.retail.telecomitalia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 11:45:25.025592 2026] [security2:error] [pid 9067:tid 9067] [client 95.246.82.11:62815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||reyadecostarica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "reyadecostarica.com"] [uri "/wp-json/wp/v2/users"] [unique_id "airYFfQPR5nsFHVyb5bQ5QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 10:40:17
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.246.82.11 (host-95-246-82-11.retail.telecomi ...
show more
(mod_security) mod_security (id:225170) triggered by 95.246.82.11 (host-95-246-82-11.retail.telecomitalia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 06:40:09.661017 2026] [security2:error] [pid 1735:tid 1735] [client 95.246.82.11:56984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jazziiafoundation.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aiqQiempK-7Dkm4bq40r8gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:11:00
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 95.246.82.11 (host-95-246-82-11.retail.telecomi ...
show more
(mod_security) mod_security (id:225170) triggered by 95.246.82.11 (host-95-246-82-11.retail.telecomitalia.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:10:55.576761 2026] [security2:error] [pid 1651:tid 1651] [client 95.246.82.11:53755] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "convtek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aifmr_hlkwJZ7q-No4EaKAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Dolphi
2026-06-09 10:00:10
(1 week ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack