๐ฉ๐ช
konseptit
2026-06-27 05:07:34
(3 hours ago)
(wordpress) Failed wordpress login from 103.126.30.49 (ID/Indonesia/gtw-jkt-30-49.integrasia.id)
Brute-Force
๐ณ๐ฑ
Site.eu
2026-06-27 03:03:49
(5 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-26 12:53:05
(19 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 12:30:28
(19 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 08:30:25.487149 2026] [security2:error] [pid 5945:tid 5945] [client 103.126.30.49:60275] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.126.30.49 (+1 hits since last alert)|atidysort.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "atidysort.com"] [uri "/xmlrpc.php"] [unique_id "aj5w4cGaIgZq1vFPgKQ9ogAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 08:57:59
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 04:57:56.275754 2026] [security2:error] [pid 23113:tid 23113] [client 103.126.30.49:54959] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.126.30.49 (+1 hits since last alert)|answeringilliana.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "answeringilliana.com"] [uri "/xmlrpc.php"] [unique_id "aj4_FBDol5BQ7qHgw98_MQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
sasbau
2026-06-26 07:55:13
(1 day ago)
103.126.30.49 - - [26/Jun/2026:09:54:52 +0200] "POST /xmlrpc.php HTTP/1.1" 403 146 "-" "WordPress.co ...
show more
103.126.30.49 - - [26/Jun/2026:09:54:52 +0200] "POST /xmlrpc.php HTTP/1.1" 403 146 "-" "WordPress.com; https://wordpress.com"
103.126.30.49 - - [26/Jun/2026:09:55:02 +0200] "POST /xmlrpc.php HTTP/1.1" 403 146 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
103.126.30.49 - - [26/Jun/2026:09:55:13 +0200] "POST /xmlrpc.php HTTP/1.1" 403 146 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-26 06:54:05
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐จ๐ฆ
Dunham Support
2026-06-26 05:19:52
(1 day ago)
(wordpress) Failed wordpress login from 103.126.30.49 (ID/Indonesia/gtw-jkt-30-49.integrasia.id)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-26 04:42:44
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 00:42:40.961732 2026] [security2:error] [pid 7273:tid 7333] [client 103.126.30.49:60361] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.126.30.49 (+1 hits since last alert)|georgementz.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgementz.org"] [uri "/xmlrpc.php"] [unique_id "aj4DQJD_aYnOk41LiD39hQAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 14:58:00
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 10:57:55.373172 2026] [security2:error] [pid 2640:tid 2640] [client 103.126.30.49:58610] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.126.30.49 (+1 hits since last alert)|sneedvillefarmersmarket.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sneedvillefarmersmarket.com"] [uri "/xmlrpc.php"] [unique_id "aj1B82U3Zwgqz3ByQOqG8wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Dave Hansen
2026-06-25 14:24:05
(1 day ago)
(wordpress) Failed wordpress login from 103.126.30.49 (ID/Indonesia/gtw-jkt-30-49.integrasia.id)
Brute-Force
Anonymous
2026-06-25 12:54:40
(1 day ago)
Attac
Brute-Force
๐ฆ๐บ
screwlooseit.com.au
2026-06-25 12:51:07
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ID/Indonesia/gtw-jkt-30-49.integrasia.id
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 12:23:17
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.126.30.49 (gtw-jkt-30-49.integrasia.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 08:23:14.189424 2026] [security2:error] [pid 16181:tid 16181] [client 103.126.30.49:51549] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.126.30.49 (+1 hits since last alert)|edmestonfd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "edmestonfd.com"] [uri "/xmlrpc.php"] [unique_id "aj0dslNzGqjxX9GcyYbXEAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-06-25 09:58:05
(1 day ago)
Wordpress Login or XMLRPC abuse
Web App Attack