๐บ๐ธ
TPI-Abuse
2026-06-26 04:43:33
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 106.214.9.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.9.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 00:43:20.082140 2026] [security2:error] [pid 15321:tid 15321] [client 106.214.9.37:7223] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.9.37 (+1 hits since last alert)|climasyequipos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "climasyequipos.com"] [uri "/xmlrpc.php"] [unique_id "aj4DaH_HTWNxSjBbK5RJLAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-26 04:42:23
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-26 03:34:37
(4 days ago)
3.348 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
integrantservices.com
2026-06-26 02:58:42
(4 days ago)
(wordpress) Failed wordpress login from 106.214.9.37 (IN/India/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-26 02:29:25
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 106.214.9.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.9.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 22:29:12.373989 2026] [security2:error] [pid 23793:tid 23793] [client 106.214.9.37:16509] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.9.37 (+1 hits since last alert)|globaldentalservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "globaldentalservices.com"] [uri "/xmlrpc.php"] [unique_id "aj3j-Mzjr-gSs3HHci9d2QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
stefaniak41500
2026-06-26 01:56:13
(4 days ago)
Shield Guard: Scanner: wordpress (+70) | Chemin suspect: /xmlrpc.php | xmlrpc.php bloquรฉ
Web App Attack
Port Scan
๐ณ๐ฑ
ConsulHosting
2026-06-26 01:11:57
(4 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
masterguru
2026-06-26 00:24:38
(4 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-25 21:41:50
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 106.214.9.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 106.214.9.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 17:41:37.254860 2026] [security2:error] [pid 25095:tid 25095] [client 106.214.9.37:6524] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.214.9.37 (+1 hits since last alert)|eta-mct.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eta-mct.com"] [uri "/xmlrpc.php"] [unique_id "aj2gkf33sb_GQI-M3gyI1gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-17 05:23:14
(1 week ago)
[redacted] 106.214.9.37 - - [17/Jun/2026:07:22:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 106.214.9.37 - - [17/Jun/2026:07:22:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site81489633.com"
[redacted] 106.214.9.37 - - [17/Jun/2026:07:22:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.1; http://site27238435.com"
[redacted] 106.214.9.37 - - [17/Jun/2026:07:22:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 106.214.9.37 - - [17/Jun/2026:07:23:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 106.214.9.37 - - [17/Jun/2026:07:23:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐น๐ท
Threat.live
2026-05-30 11:50:08
(1 month ago)
Suspicious Connection Attempts
Brute-Force
๐ซ๐ท
Petre 21_ip
2026-05-26 07:11:56
(1 month ago)
2026-05-26T09:11:54.920199+02:00 vmi2775508 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:50:56:5c:a7:cf:c ...
show more
2026-05-26T09:11:54.920199+02:00 vmi2775508 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:50:56:5c:a7:cf:c0:69:11:b3:85:db:08:00 SRC=106.214.9.37 DST=155.133.26.57 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=29446 DF PROTO=TCP SPT=25371 DPT=23 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ณ๐ฑ
debestelapp
2026-05-14 16:05:06
(1 month ago)
Web App Attack
๐ซ๐ท
dynamix
2026-05-14 10:16:32
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-05-14 06:49:58
(1 month ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack