Anonymous
2026-07-29 04:06:14
(1 day ago)
[redacted] 102.66.187.39 - - [29/Jul/2026:06:05:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "W ...
show more
[redacted] 102.66.187.39 - - [29/Jul/2026:06:05:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.66.187.39 - - [29/Jul/2026:06:05:41 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 102.66.187.39 - - [29/Jul/2026:06:05:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 102.66.187.39 - - [29/Jul/2026:06:06:02 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.66.187.39 - - [29/Jul/2026:06:06:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 18:54:28
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:54:21.163051 2026] [security2:error] [pid 1277924:tid 1277924] [client 102.66.187.39:54241] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.66.187.39 (+1 hits since last alert)|airdriedrivingschool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "airdriedrivingschool.com"] [uri "/xmlrpc.php"] [unique_id "amj63TmIgiSCmrHQCpUqXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
nationaleventpros.com
2026-07-28 18:20:26
(2 days ago)
WordPress login attempt
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-28 17:51:46
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 13:51:37.669133 2026] [security2:error] [pid 16327:tid 16327] [client 102.66.187.39:9229] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.66.187.39 (+1 hits since last alert)|rohanbyles.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rohanbyles.com.au"] [uri "/xmlrpc.php"] [unique_id "amjsKXQobXUbifARvcRRmwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 14:48:48
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 10:48:44.633870 2026] [security2:error] [pid 2299216:tid 2299216] [client 102.66.187.39:51340] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.66.187.39 (+1 hits since last alert)|digi-estudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "digi-estudio.com"] [uri "/xmlrpc.php"] [unique_id "amjBTGRV_xWby42f_WkQWQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Tha_14
2026-07-28 14:17:50
(2 days ago)
Limit on login attempts is reached
Brute-Force
πΊπΈ
WeekendWeb
2026-07-28 14:16:49
(2 days ago)
Wordpress Vunerability attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 13:18:11
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:18:03.427692 2026] [security2:error] [pid 1110669:tid 1110669] [client 102.66.187.39:20651] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.66.187.39 (+1 hits since last alert)|braintechsoftwaresolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "braintechsoftwaresolutions.com"] [uri "/xmlrpc.php"] [unique_id "amisC5RbjzjaYSq9iCHs2gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-27 18:08:12
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 17:09:24
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 102.66.187.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:09:09.727196 2026] [security2:error] [pid 3880742:tid 3880742] [client 102.66.187.39:17699] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.66.187.39 (+1 hits since last alert)|agworldmissions.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "agworldmissions.org"] [uri "/xmlrpc.php"] [unique_id "ameQtcGeh-ag_r4u9LYQgwAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Kenshin869
2026-07-27 16:34:51
(3 days ago)
Wordpress unauthorized access attempt
Brute-Force
Anonymous
2026-07-14 19:42:19
(2 weeks ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Exploited Host
Bad Web Bot