๐ซ๐ท
Kenshin869
2026-07-31 21:24:56
(2 hours ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-31 18:54:06
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 14:53:55.385998 2026] [security2:error] [pid 1124888:tid 1124888] [client 106.214.222.128:49153] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.222.128 (+1 hits since last alert)|wildlandconservancy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wildlandconservancy.com"] [uri "/xmlrpc.php"] [unique_id "amzvQ7uaKOxwrcv2D7ODKQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-07-31 18:19:58
(5 hours ago)
106.214.222.128 - - [01/Aug/2026:02:19:37 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "WordPress ...
show more
106.214.222.128 - - [01/Aug/2026:02:19:37 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "WordPress.com; https://wordpress.com"
106.214.222.128 - - [01/Aug/2026:02:19:47 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "WordPress.com; https://wordpress.com"
106.214.222.128 - - [01/Aug/2026:02:19:58 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-31 17:52:30
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:52:16.623250 2026] [security2:error] [pid 1025669:tid 1025669] [client 106.214.222.128:63099] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.222.128 (+1 hits since last alert)|agkgt.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "agkgt.org"] [uri "/xmlrpc.php"] [unique_id "amzg0JTBrQYm81tleTB4_QAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 16:18:42
(7 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 12:18:32.554087 2026] [security2:error] [pid 26208:tid 26208] [client 106.214.222.128:63463] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.222.128 (+1 hits since last alert)|arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arsenalfordemocracy.com"] [uri "/xmlrpc.php"] [unique_id "amzK2G9ZTK8frfElsU0L7AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-31 06:23:44
(17 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-30 13:20:06
(1 day ago)
Wordfence waf block on floridaactioncommittee
Web App Attack
๐ง๐ช
cmbplf
2026-07-30 07:32:50
(1 day ago)
3.596 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
IndigoRidge
2026-07-30 07:30:42
(1 day ago)
106.214.222.128 - - [30/Jul/2026:03:29:38 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5782 "-" "WordPress ...
show more
106.214.222.128 - - [30/Jul/2026:03:29:38 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5782 "-" "WordPress.com; https://wordpress.com"
106.214.222.128 - - [30/Jul/2026:03:30:00 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5782 "-" "WordPress.com; https://wordpress.com"
106.214.222.128 - - [30/Jul/2026:03:30:10 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5782 "-" "WordPress.com; https://wordpress.com"
106.214.222.128 - - [30/Jul/2026:03:30:31 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5782 "-" "WordPress.com; https://wordpress.com"
106.214.222.128 - - [30/Jul/2026:03:30:42 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5782 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 07:12:55
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 03:12:41.509733 2026] [security2:error] [pid 406278:tid 406278] [client 106.214.222.128:56881] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.222.128 (+1 hits since last alert)|cemesur-vision21.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cemesur-vision21.com"] [uri "/xmlrpc.php"] [unique_id "amr5ad-RXfZQ8vKIQ84IzQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 05:43:00
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 01:42:50.461378 2026] [security2:error] [pid 498729:tid 498729] [client 106.214.222.128:62355] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.222.128 (+1 hits since last alert)|fetchamreadingroom.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fetchamreadingroom.org"] [uri "/xmlrpc.php"] [unique_id "amrkWqKFtTMwLPiJchs75QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-07-30 04:39:00
(1 day ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 days ago)
Automated Apache web application probing in selected 24h window; attempts=30, unique_paths=1, error_ ...
show more
Automated Apache web application probing in selected 24h window; attempts=30, unique_paths=1, error_responses=24; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 days ago)
Apache probe; attempts=30; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 06:47:39
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.222.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 02:47:30.131001 2026] [security2:error] [pid 12386:tid 12386] [client 106.214.222.128:53142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.222.128 (+1 hits since last alert)|modmove.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "modmove.com"] [uri "/xmlrpc.php"] [unique_id "ammiAvOUb2UWI4os_1uNEwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack