๐บ๐ธ
SX Communications
2026-07-22 16:04:17
(17 hours ago)
HTTP application-layer DoS / botnet traffic from 106.219.122.211: repeated high-cost dynamic page an ...
show more
HTTP application-layer DoS / botnet traffic from 106.219.122.211: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐ง๐ช
cmbplf
2026-07-07 17:33:01
(2 weeks ago)
8.379 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-07-07 16:43:33
(2 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-07 16:27:26
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 106.219.122.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.122.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 07 12:27:21.368394 2026] [security2:error] [pid 15883:tid 15883] [client 106.219.122.211:21383] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.122.211 (+1 hits since last alert)|deborahbein.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "deborahbein.com"] [uri "/xmlrpc.php"] [unique_id "ak0o6TG-izXdTWuSkxcQcwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-07 16:02:48
(2 weeks ago)
(wordpress) Failed wordpress login from 106.219.122.211 (IN/India/-)
Brute-Force
๐ช๐จ
icp77
2026-07-07 15:45:00
(2 weeks ago)
Abuse DDoS
DDoS Attack
Port Scan
Brute-Force
Exploited Host
Web App Attack
SSH
FTP Brute-Force
Hacking
SQL Injection
Anonymous
2026-07-07 15:15:37
(2 weeks ago)
[da.kdns.gr] httpd-xmlrpc-post: sites=www.diadromi.com; logs=/var/log/httpd/domains/diadromi.com.log ...
show more
[da.kdns.gr] httpd-xmlrpc-post: sites=www.diadromi.com; logs=/var/log/httpd/domains/diadromi.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-07 15:14:35
(2 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack
๐ซ๐ท
dynamix
2026-07-07 15:11:23
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-07 14:46:49
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 106.219.122.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.122.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 07 10:46:43.516507 2026] [security2:error] [pid 24695:tid 24695] [client 106.219.122.211:31298] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.122.211 (+1 hits since last alert)|livingawakenedbook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "livingawakenedbook.com"] [uri "/xmlrpc.php"] [unique_id "ak0RUzGRc21OYna9ec09cAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-07 13:47:27
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 106.219.122.211 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.122.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 07 09:47:19.775769 2026] [security2:error] [pid 20767:tid 20767] [client 106.219.122.211:4530] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.122.211 (+1 hits since last alert)|proyectando.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "proyectando.com"] [uri "/xmlrpc.php"] [unique_id "ak0DZ9S3E-VRzR9SG6p3agAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-07 13:47:25
(2 weeks ago)
(wordpress) Failed wordpress login from 106.219.122.211 (IN/India/-)
Brute-Force
๐ฆ๐บ
AWW-Admin
2026-07-07 13:46:21
(2 weeks ago)
(wordpress) Failed wordpress login from 106.219.122.211 (IN/India/-)
Brute-Force
๐บ๐ธ
xmission.com
2026-07-07 13:22:04
(2 weeks ago)
106.219.122.211 - - [07/Jul/2026:07:22:04 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by ...
show more
106.219.122.211 - - [07/Jul/2026:07:22:04 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
...
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-07-06 17:38:00
(2 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot