๐จ๐ญ
Mario Bretscher
2026-07-27 20:49:11
(16 hours ago)
Jul 27 22:48:39 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[2227146]: Authentication failure for ...
show more
Jul 27 22:48:39 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[2227146]: Authentication failure for tubegrabe-stafel.ch from 96.9.79.154
Jul 27 22:49:09 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[2227794]: Authentication failure for tubegrabe-stafel.ch from 96.9.79.154
...
show less
Web Spam
Anonymous
2026-07-27 19:21:03
(17 hours ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-27 15:08:23
(21 hours ago)
(wordpress) Failed wordpress login from 96.9.79.154 (KH/Cambodia/Phnom Penh/Phnom Penh/154.79.9.96.s ...
show more
(wordpress) Failed wordpress login from 96.9.79.154 (KH/Cambodia/Phnom Penh/Phnom Penh/154.79.9.96.sinet.com.kh)
show less
Brute-Force
๐ฉ๐ช
Tsumugi Kotobuki
2026-07-27 14:01:57
(23 hours ago)
Web Scan (L7) | Paths: /xmlrpc.php | Codes: 444(1x) | UA: Mozilla/5.0 (Windows NT 6.2; x64) AppleWeb ...
show more
Web Scan (L7) | Paths: /xmlrpc.php | Codes: 444(1x) | UA: Mozilla/5.0 (Windows NT 6.2; x64) AppleWebKit/537.36 (KHT... | rDNS: 154.79.9.96.sinet.com.kh | F2B/angie-honeypot@2026-07-27T14:01:57Z
show less
Bad Web Bot
Web App Attack
Hacking
๐ฎ๐น
ciccio diddo
2026-07-27 08:27:42
(1 day ago)
CMS/WP Exploit xmlrpc port:Tcp/80,443
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 03:27:35
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 96.9.79.154 (154.79.9.96.sinet.com.kh): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 96.9.79.154 (154.79.9.96.sinet.com.kh): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 23:27:27.406095 2026] [security2:error] [pid 2576260:tid 2576260] [client 96.9.79.154:37005] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realclean.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ambQH3kLO4US70bqJMY9MAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-07-25 08:53:55
(3 days ago)
-:443 96.9.79.154 - - [25/Jul/2026:10:53:54 +0200] - "POST /xmlrpc.php HTTP/1.1" 404 6371 "-" "Mozil ...
show more
-:443 96.9.79.154 - - [25/Jul/2026:10:53:54 +0200] - "POST /xmlrpc.php HTTP/1.1" 404 6371 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/63.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-24 09:07:35
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 96.9.79.154 (154.79.9.96.sinet.com.kh): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 96.9.79.154 (154.79.9.96.sinet.com.kh): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:07:27.611504 2026] [security2:error] [pid 3653795:tid 3653795] [client 96.9.79.154:27362] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gerrytolentino.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gerrytolentino.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amMrT-vuO33Yhi-PI2e9OAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-23 09:05:09
(5 days ago)
Xmlrpc Caught (7)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 06:25:00
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 96.9.79.154 (154.79.9.96.sinet.com.kh): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 96.9.79.154 (154.79.9.96.sinet.com.kh): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 02:24:53.357405 2026] [security2:error] [pid 1742478:tid 1742478] [client 96.9.79.154:22172] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||smoothiessoupssalads.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "smoothiessoupssalads.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amGztXX6bnCOHs_Oo331yQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 08:54:37
(6 days ago)
Fail2ban filtered
...
Web App Attack
Anonymous
2026-07-22 08:35:06
(6 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 10:12:03
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 96.9.79.154 (154.79.9.96.sinet.com.kh): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 96.9.79.154 (154.79.9.96.sinet.com.kh): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:11:56.712841 2026] [security2:error] [pid 21481:tid 21481] [client 96.9.79.154:49328] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||garanta.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "garanta.co"] [uri "/wp-json/wp/v2/users"] [unique_id "al9F7HoWI9we-WKwiE_w2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-21 05:05:58
(1 week ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/ ...
show more
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Opera/70.0.0.0 Safari/537.36
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-07-14 04:48:06
(2 weeks ago)
[TueJul1406:48:02.8038222026][security2:error][pid1605222:tid1605233][client96.9.79.154:0]ModSecurit ...
show more
[TueJul1406:48:02.8038222026][security2:error][pid1605222:tid1605233][client96.9.79.154:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"mgpublishing.ch\"][uri\"/xmlrpc.php\"][unique_id\"alW_gp8m-kLyWdeTxdD7lAAAAEc\"]
show less
Port Scan
Brute-Force
Web App Attack