Anonymous
2026-06-17 14:08:05
(3 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 12:58:24
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 08:58:17.748850 2026] [security2:error] [pid 18360:tid 18360] [client 106.219.121.201:10509] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thehealthyplaceclayton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thehealthyplaceclayton.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajKZ6XEg-UPJNEAXthGpBwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 04:19:46
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 00:19:40.015091 2026] [security2:error] [pid 5479:tid 5479] [client 106.219.121.201:7293] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.121.201 (+1 hits since last alert)|hawarcenter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hawarcenter.com"] [uri "/xmlrpc.php"] [unique_id "ajIgXDN5FZVU5i7rs_S_lgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 22:30:57
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 18:30:50.394471 2026] [security2:error] [pid 32259:tid 32259] [client 106.219.121.201:9627] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.121.201 (+1 hits since last alert)|aandbnaturalfoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aandbnaturalfoods.com"] [uri "/xmlrpc.php"] [unique_id "ajHOmgb3CeYFPa5oPBOSTQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 22:06:20
(19 hours ago)
[redacted] 106.219.121.201 - - [17/Jun/2026:00:05:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 106.219.121.201 - - [17/Jun/2026:00:05:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site65868892.com"
[redacted] 106.219.121.201 - - [17/Jun/2026:00:05:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 106.219.121.201 - - [17/Jun/2026:00:05:58 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site46806164.com"
[redacted] 106.219.121.201 - - [17/Jun/2026:00:06:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 106.219.121.201 - - [17/Jun/2026:00:06:19 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.1; http://site44115850.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-16 21:41:11
(19 hours ago)
[redacted] 106.219.121.201 - - [16/Jun/2026:23:40:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 106.219.121.201 - - [16/Jun/2026:23:40:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 106.219.121.201 - - [16/Jun/2026:23:40:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
[redacted] 106.219.121.201 - - [16/Jun/2026:23:40:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 106.219.121.201 - - [16/Jun/2026:23:41:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 106.219.121.201 - - [16/Jun/2026:23:41:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 19:54:58
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 15:54:54.690264 2026] [security2:error] [pid 3391:tid 3391] [client 106.219.121.201:3908] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.121.201 (+1 hits since last alert)|rdhtrucking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rdhtrucking.com"] [uri "/xmlrpc.php"] [unique_id "ajGqDtK5eZtdb-vg3X_BZgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NewWavesApp
2026-06-16 18:52:28
(22 hours ago)
(wordpress) Failed wordpress login from 106.219.121.201 (IN/India/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 18:47:07
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 14:47:03.176512 2026] [security2:error] [pid 14482:tid 14482] [client 106.219.121.201:4574] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.121.201 (+1 hits since last alert)|websitesforauthors.design|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "websitesforauthors.design"] [uri "/xmlrpc.php"] [unique_id "ajGaJ8e9vldsqCb0iO6PmwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-16 16:37:36
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 15:49:47
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:49:39.978157 2026] [security2:error] [pid 2083:tid 2083] [client 106.219.121.201:10745] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.121.201 (+1 hits since last alert)|adona.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "adona.org"] [uri "/xmlrpc.php"] [unique_id "ajFwk9od3RZH64IlDNvGPwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 15:16:39
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.121.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:16:33.593977 2026] [security2:error] [pid 8548:tid 8554] [client 106.219.121.201:23421] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.121.201 (+1 hits since last alert)|kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kettlehill.com"] [uri "/xmlrpc.php"] [unique_id "ajFo0SlTEfKruo62oyDXDQAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(3 weeks ago)
Aisuru(Mirai variant) DDoS | Incident ID: 22ada211-5b5c-463a-b46f-60fd11dc639d
DDoS Attack
๐ต๐ฑ
nfsec.pl
2026-02-25 07:51:30
(3 months ago)
Detected: TCP scan on port: 445 with flags: SYN
Port Scan
๐ช๐ธ
Global Cyber Police
2025-07-28 07:54:07
(10 months ago)
Malicious bot activity detected: Hitting honeypot page. Part of massive botnet.
DDoS Attack
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Web App Attack