🇺🇸
kosada.com
2026-08-31 10:31:43
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
WeekendWeb
2026-08-17 11:08:15
(3 weeks ago)
Wordpress Vunerability attack
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 06:58:39
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:58:30.945565 2026] [security2:error] [pid 7265:tid 7265] [client 103.25.46.39:59782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.25.46.39 (+1 hits since last alert)|superzilla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "superzilla.com"] [uri "/xmlrpc.php"] [unique_id "aoKxFrwAKdDA73tv88Rx5wAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 08:22:53
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 04:22:45.636755 2026] [security2:error] [pid 85717:tid 85717] [client 103.25.46.39:52485] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.25.46.39 (+1 hits since last alert)|inverzona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "inverzona.com"] [uri "/xmlrpc.php"] [unique_id "aoAh1QiWKuR8uskVNBra0AAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-08-07 09:20:58
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-08-07 08:56:26
(1 month ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 05:43:08
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 01:43:02.874159 2026] [security2:error] [pid 3450266:tid 3450266] [client 103.25.46.39:60499] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.25.46.39 (+1 hits since last alert)|bonesband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bonesband.com"] [uri "/xmlrpc.php"] [unique_id "anVwZmxDk3jdiQRTEESVrgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-06 08:17:10
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.space | URI: /xmlrpc.php | UA: WordPress.com; https://wordpress.com | BODY: <?xml version="1.0"?><methodCall><methodName>metaWeblog.newPost</methodName><params><param><value><string>1</string></value></param><param><value><string>31023</string></value></param><param><value><string>31023</string></value></param><param><value><struct><member><name>title</name><value><string>3fai6cosgudu7q</string></value></member><member><name>description</name><value><string>ol0ms95hw99smacalv74dmu
show less
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-08-04 07:50:25
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-08-04 07:37:04
(1 month ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-31 06:24:54
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 02:24:49.624036 2026] [security2:error] [pid 755083:tid 755083] [client 103.25.46.39:59445] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.25.46.39 (+1 hits since last alert)|rwabutazafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rwabutazafoundation.org"] [uri "/xmlrpc.php"] [unique_id "amw_sXgs_RQ-QGicxI6z1wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-07-30 07:42:34
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
integrantservices.com
2026-07-28 07:05:29
(1 month ago)
(wordpress) Failed wordpress login from 103.25.46.39 (IN/India/-)
Brute-Force
🇯🇵
rafale2k
2026-07-24 06:48:23
(1 month ago)
WordPress Brute Force
Brute-Force
Web App Attack
🇪🇸
alferez
2026-07-23 11:29:21
(1 month ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack