๐ฉ๐ช
F242
2026-06-17 16:45:42
(2 days ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 14:51:25
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.co ...
show more
(mod_security) mod_security (id:240335) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 10:51:18.502751 2026] [security2:error] [pid 1471:tid 1471] [client 103.217.111.69:52710] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.217.111.69 (+1 hits since last alert)|my-spec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "my-spec.com"] [uri "/xmlrpc.php"] [unique_id "ajARZg_FFqCTDc6rjIyC_gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-06-12 17:10:13
(1 week ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-12 07:52:52
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.co ...
show more
(mod_security) mod_security (id:225170) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 03:52:46.421281 2026] [security2:error] [pid 25714:tid 25714] [client 103.217.111.69:59439] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kiinlog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kiinlog.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiu6zhnSTJ5PZ5NvSh60rwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-11 16:08:24
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-08 03:58:47
(1 week ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=physio-kinisi.gr; logs=/var/log/httpd/domains/physio-kinisi ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=physio-kinisi.gr; logs=/var/log/httpd/domains/physio-kinisi.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ซ๐ท
applemooz
2026-06-07 00:30:30
(1 week ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
Anonymous
2026-02-05 02:36:35
(4 months ago)
SMTP brute force - auth failed
Brute-Force
Exploited Host
Anonymous
2026-02-01 20:33:18
(4 months ago)
SMTP brute force - auth failed
Brute-Force
Exploited Host
๐ฎ๐น
VHosting
2026-01-12 09:12:41
(5 months ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐บ๐ธ
myagent.site
2025-12-10 20:46:25
(6 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-10 19:03:33
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.co ...
show more
(mod_security) mod_security (id:225170) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 14:03:26.486273 2025] [security2:error] [pid 7583:tid 7583] [client 103.217.111.69:64893] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jimrichardart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jimrichardart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTnD_moTVZkTv8Nku-y-1QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 15:23:16
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.co ...
show more
(mod_security) mod_security (id:225170) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 10:23:10.706254 2025] [security2:error] [pid 25741:tid 25741] [client 103.217.111.69:50405] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jillbauman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jillbauman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTmQXsjtfeTOHzSym3B8eQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 12:00:28
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.co ...
show more
(mod_security) mod_security (id:225170) triggered by 103.217.111.69 (69.111.217.103.dotinternetbd.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 07:00:23.742726 2025] [security2:error] [pid 22633:tid 22633] [client 103.217.111.69:55924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||weddingmusicguitar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "weddingmusicguitar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTlg1-S0NX5hV9Mp57DO9AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
teamsecure
2025-12-10 07:28:58
(6 months ago)
Banned for trying to access xmlrpc
Web App Attack