Anonymous
2026-07-25 12:35:03
(4 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
konseptit
2026-07-25 11:50:44
(5 hours ago)
(wordpress) Failed wordpress login from 102.164.1.248 (cgnat.capricom.net)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-24 16:00:29
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the la ...
show more
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:00:17.720034 2026] [security2:error] [pid 1527371:tid 1527371] [client 102.164.1.248:51661] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.164.1.248 (+1 hits since last alert)|vintageamptubes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vintageamptubes.com"] [uri "/xmlrpc.php"] [unique_id "amOMEVVHsgsWjjajhGfcrgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 14:22:07
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-07-21 17:57:02
(3 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack/12.1; WordPress ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack/12.1; WordPress/6.4; http://site11044563.com
show less
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-20 15:08:50
(5 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-20 12:15:29
(5 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ZA/South Africa/cgnat.capricom.net
Web App Attack
๐บ๐ธ
kosada.com
2026-06-29 05:43:50
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-06-18 17:00:19
(1 month ago)
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show more
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /wishlist/index/add/product/11168/form_key/1HbtXZMdBHiFIqfU/ | UA: Opera/8.19.(X11; Linux i686; el-CY) Presto/2.9.168 Version/10.00 | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-06-18 10:38:40
(1 month ago)
๐ฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 15:26:42
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the la ...
show more
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:26:37.130035 2026] [security2:error] [pid 4507:tid 4507] [client 102.164.1.248:53860] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.164.1.248 (+1 hits since last alert)|abeltours.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abeltours.com"] [uri "/xmlrpc.php"] [unique_id "aiGZLUhm-M7tNvH4gEg3dgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 19:57:01
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the la ...
show more
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 15:56:53.022462 2026] [security2:error] [pid 23747:tid 23747] [client 102.164.1.248:52967] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.164.1.248 (+1 hits since last alert)|cemesur-vision21.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cemesur-vision21.com"] [uri "/xmlrpc.php"] [unique_id "aiCHBR_z__LafcxkkYQDiQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 07:13:55
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the la ...
show more
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 03:13:51.920973 2026] [security2:error] [pid 16478:tid 16492] [client 102.164.1.248:56814] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.164.1.248 (+1 hits since last alert)|maroontribe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "maroontribe.com"] [uri "/xmlrpc.php"] [unique_id "ah0xLz53eQ3VjVXa1IVvUwAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 06:48:21
(1 month ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-01 05:54:45
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the la ...
show more
(mod_security) mod_security (id:240335) triggered by 102.164.1.248 (cgnat.capricom.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 01:54:39.879856 2026] [security2:error] [pid 24982:tid 24996] [client 102.164.1.248:55732] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.164.1.248 (+1 hits since last alert)|wnsi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wnsi.org"] [uri "/xmlrpc.php"] [unique_id "ah0enztnh5d0XZgIEtt3bAAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack