๐บ๐ธ
TPI-Abuse
2026-07-23 05:48:29
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 113.211.121.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 113.211.121.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:48:24.108100 2026] [security2:error] [pid 3948983:tid 3948983] [client 113.211.121.0:31395] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 113.211.121.0 (+1 hits since last alert)|odysseydogasporlari.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "odysseydogasporlari.com"] [uri "/xmlrpc.php"] [unique_id "amGrKBrAtZ55sTSGkrlxhgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-23 05:43:02
(10 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
MY/Malaysia/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:20:04
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 113.211.121.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 113.211.121.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:19:56.590431 2026] [security2:error] [pid 2346955:tid 2346955] [client 113.211.121.0:38841] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 113.211.121.0 (+1 hits since last alert)|kadinisi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kadinisi.org"] [uri "/xmlrpc.php"] [unique_id "amGkfKIMLFSxenE07_EodwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 03:14:51
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 113.211.121.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 113.211.121.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 23:14:46.764581 2026] [security2:error] [pid 1773483:tid 1773483] [client 113.211.121.0:51867] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 113.211.121.0 (+1 hits since last alert)|igolfallday.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "igolfallday.com"] [uri "/xmlrpc.php"] [unique_id "amGHJlK10bdWRErUTldDHwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-23 03:13:35
(13 hours ago)
(wordpress) Failed wordpress login from 113.211.121.0 (MY/Malaysia/-)
Brute-Force
๐ซ๐ฎ
YF
2026-07-23 01:31:38
(14 hours ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-23 01:01:07
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 113.211.121.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 113.211.121.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 21:01:01.293769 2026] [security2:error] [pid 1578281:tid 1578281] [client 113.211.121.0:4725] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 113.211.121.0 (+1 hits since last alert)|phoboschildren.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "phoboschildren.com"] [uri "/xmlrpc.php"] [unique_id "amFnzXdUdIA4ho24XhHuaQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 00:58:52
(15 hours ago)
(wordpress) Failed wordpress login from 113.211.121.0 (MY/Malaysia/-)
Brute-Force
๐ฉ๐ช
rh24
2026-07-22 09:43:00
(1 day ago)
(xmlrpc_405) XMLRPC-Bot 405 113.211.121.0 (MY/Malaysia/-)
Hacking
๐ช๐ธ
masterguru
2026-07-22 07:00:23
(1 day ago)
(xmlrpc) Failed xmlrpc access from 113.211.121.0 (MY/Malaysia/-): 5 in the last 3600 secs (0-122)
Hacking
๐ซ๐ท
bazter.pro
2026-07-22 04:05:37
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-22 03:33:44
(1 day ago)
(wordpress) Failed wordpress login from 113.211.121.0 (MY/Malaysia/Kuala Lumpur/Kuala Lumpur/-)
Brute-Force
๐ฑ๐ป
garmtech.com
2026-07-21 10:13:08
(2 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ซ๐ท
dynamix
2026-07-21 09:55:22
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-21 08:56:11
(2 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack