🇩🇪
conseilgouz
2026-08-04 11:47:47
(1 month ago)
coe-7 : Trying access unauthorized files/dir=>//wp-includes/ID3/license.txt
Hacking
Anonymous
2026-08-04 11:46:42
(1 month ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
TPI-Abuse
2026-08-04 11:45:56
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 52.38.242.57 (ec2-52-38-242-57.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 52.38.242.57 (ec2-52-38-242-57.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 07:45:51.577722 2026] [security2:error] [pid 1382281:tid 1382281] [client 52.38.242.57:51281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||suswastima.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "suswastima.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "anHQ76EDplvl1sy9XxTBEQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-08-04 11:33:30
(1 month ago)
25.604 requests with url.path */xmlrpc.php
25.555 requests with url.path //xmlrpc.php
11.757 requ ...
show more
25.604 requests with url.path */xmlrpc.php
25.555 requests with url.path //xmlrpc.php
11.757 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-04 11:30:47
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 52.38.242.57 (ec2-52-38-242-57.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 52.38.242.57 (ec2-52-38-242-57.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 07:30:39.251844 2026] [security2:error] [pid 1566243:tid 1566243] [client 52.38.242.57:56203] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dandksupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dandksupply.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "anHNXwmxLebOWxdYpI2CvAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-04 11:22:38
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇮🇱
Dolphi
2026-08-04 11:20:02
(1 month ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
🇩🇪
abdubhai
2026-08-04 11:17:02
(1 month ago)
52.38.242.57 - - [04/Aug/2026:16
...
Brute-Force
Anonymous
2026-08-04 11:10:45
(1 month ago)
[redacted] 52.38.242.57 - - [04/Aug/2026:13:10:29 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "M ...
show more
[redacted] 52.38.242.57 - - [04/Aug/2026:13:10:29 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 52.38.242.57 - - [04/Aug/2026:13:10:31 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 52.38.242.57 - - [04/Aug/2026:13:10:32 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 52.38.242.57 - - [04/Aug/2026:13:10:34 +0200] "POST //xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 52.38.242.57 - - [04/Aug/2026:13:10:35 +0200]
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 11:10:28
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 52.38.242.57 (ec2-52-38-242-57.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 52.38.242.57 (ec2-52-38-242-57.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 07:10:23.035091 2026] [security2:error] [pid 4082955:tid 4082955] [client 52.38.242.57:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.upskirtcrazy.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "anHIn_6BuOpkSSn9W5lBoQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-08-04 11:10:20
(1 month ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
🇩🇪
Ba-Yu
2026-08-04 11:07:12
(1 month ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
🇫🇷
dynamix
2026-08-04 10:56:23
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 10:54:39
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 52.38.242.57 (ec2-52-38-242-57.us-west-2.comput ...
show more
(mod_security) mod_security (id:225170) triggered by 52.38.242.57 (ec2-52-38-242-57.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 06:54:31.687932 2026] [security2:error] [pid 2016944:tid 2016944] [client 52.38.242.57:62200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.konahawaii.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.konahawaii.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "anHE51k_NPeam3B_Smj5tgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack