🇺🇸
TPI-Abuse
2026-08-25 07:19:40
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:19:35.383308 2026] [security2:error] [pid 1219377:tid 1219493] [client 106.215.151.21:1537] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.215.151.21 (+1 hits since last alert)|hoffmanandassoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hoffmanandassoc.com"] [uri "/xmlrpc.php"] [unique_id "ao1CBxZj29ZxZ2W7ZIdLawAAAhA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-08-24 08:23:15
(1 week ago)
(wordpress) Failed wordpress login from 106.215.151.21 (IN/India/Gujarat/Vadodara/-)
Brute-Force
🇩🇪
konseptit
2026-08-24 07:52:35
(1 week ago)
(wordpress) Failed wordpress login from 106.215.151.21 (IN/India/-)
Brute-Force
Anonymous
2026-08-24 07:21:41
(1 week ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=www.asteres.gr; logs=/var/log/httpd/domains/asteres.gr.log; ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=www.asteres.gr; logs=/var/log/httpd/domains/asteres.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 09:14:22
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:14:15.230630 2026] [security2:error] [pid 24861:tid 24861] [client 106.215.151.21:17953] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.215.151.21 (+1 hits since last alert)|pinetreedistrict.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pinetreedistrict.org"] [uri "/xmlrpc.php"] [unique_id "aoq5526fUyd6ZyFZRDDUhQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 11:47:52
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 07:47:44.685431 2026] [security2:error] [pid 21108:tid 21108] [client 106.215.151.21:18680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.215.151.21 (+1 hits since last alert)|mobileonlinecasinos.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mobileonlinecasinos.co"] [uri "/xmlrpc.php"] [unique_id "aomMYDkSG-lCjik9BEdaewAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-20 07:12:33
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 03:12:27.477064 2026] [security2:error] [pid 27220:tid 27220] [client 106.215.151.21:17917] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.215.151.21 (+1 hits since last alert)|sutherlandyogastudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sutherlandyogastudio.com"] [uri "/xmlrpc.php"] [unique_id "aoao29Z8ZM_8oHOFItY_egAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-19 09:13:04
(2 weeks ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 13:25:44
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 09:25:39.437077 2026] [security2:error] [pid 31214:tid 31214] [client 106.215.151.21:27342] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.215.151.21 (+1 hits since last alert)|marshdcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "marshdcs.com"] [uri "/xmlrpc.php"] [unique_id "aoRdU3C0V9hL4Nl_lttjggAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 12:11:49
(2 weeks ago)
(wordpress) Failed wordpress login from 106.215.151.21 (IN/India/Gujarat/Vadodara/-/[redacted])
Brute-Force
🇺🇸
TPI-Abuse
2026-08-16 05:50:34
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.215.151.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:50:26.126735 2026] [security2:error] [pid 23177:tid 23177] [client 106.215.151.21:31079] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.215.151.21 (+1 hits since last alert)|surviquo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "surviquo.com"] [uri "/xmlrpc.php"] [unique_id "aoFPok52HUFkE1EEppNaNwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-08-15 12:16:08
(2 weeks ago)
106.215.151.21 - - [15/Aug/2026:14:15:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5351 "-" "Jetpack/12 ...
show more
106.215.151.21 - - [15/Aug/2026:14:15:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5351 "-" "Jetpack/12.5; WordPress/6.4; http://site34921092.com" 106.215.151.21 - - [15/Aug/2026:14:15:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5351 "-" "Jetpack/12.5; WordPress/6.2; http://site40173876.com" 106.215.151.21 - - [15/Aug/2026:14:16:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5351 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
show less
Brute-Force
Web App Attack
Anonymous
2026-08-15 12:15:57
(2 weeks ago)
106.215.151.21 - - [15/Aug/2026:14:15:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 750 "-" "Jetpack by ...
show more
106.215.151.21 - - [15/Aug/2026:14:15:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 750 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
106.215.151.21 - - [15/Aug/2026:14:15:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
106.215.151.21 - - [15/Aug/2026:14:15:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 750 "-" "Jetpack/13.0; WordPress/6.2; http://site85871628.com"
106.215.151.21 - - [15/Aug/2026:14:15:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/13.0; WordPress/6.2; http://site85871628.com"
106.215.151.21 - - [15/Aug/2026:14:15:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 750 "-" "Jetpack/12.5; WordPress/6.3; http://site88144033.com"
...
show less
Brute-Force
Web App Attack
🇩🇪
ghostwarriors
2026-08-15 07:21:01
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-08-15 07:09:30
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack