๐ช๐ธ
masterguru
2026-06-12 05:22:24
(2 days ago)
(xmlrpc) Failed xmlrpc access from 123.108.206.3 (IN/India/-): 5 in the last 3600 secs (0-122)
Hacking
๐ซ๐ท
dynamix
2026-06-10 09:47:35
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-09 08:08:27
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-09 06:10:03
(5 days ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
Anonymous
2026-06-09 06:07:10
(5 days ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 10:56:09
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 06:55:55.221248 2026] [security2:error] [pid 16735:tid 16735] [client 123.108.206.3:63720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.108.206.3 (+1 hits since last alert)|yuichiro.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yuichiro.us"] [uri "/xmlrpc.php"] [unique_id "aiafu7IgAElPrexvTHO_gAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 06:05:10
(6 days ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 05:52:58
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 01:52:46.327548 2026] [security2:error] [pid 10826:tid 10826] [client 123.108.206.3:57170] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.108.206.3 (+1 hits since last alert)|kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kdgsf.xyz"] [uri "/xmlrpc.php"] [unique_id "aiZYrnSaanXTioD8pdmH2QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 02:38:01
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 22:37:47.466311 2026] [security2:error] [pid 10838:tid 10930] [client 123.108.206.3:62959] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.108.206.3 (+1 hits since last alert)|whatismetamodern.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whatismetamodern.com"] [uri "/xmlrpc.php"] [unique_id "aiYq-4EIzUo_sHBIfuRdlgAAAc8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-08 02:33:39
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-07 22:57:16
(1 week ago)
(wordpress) Failed wordpress login from 123.108.206.3 (IN/India/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-07 20:57:24
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 16:57:13.277072 2026] [security2:error] [pid 7787:tid 7787] [client 123.108.206.3:53883] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.108.206.3 (+1 hits since last alert)|medusakenya.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "medusakenya.com"] [uri "/xmlrpc.php"] [unique_id "aiXbKTymjEoRG0T7KVNF2AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-07 20:51:50
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
Kenshin869
2026-06-07 19:43:45
(1 week ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-07 17:56:15
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 123.108.206.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 13:56:05.837479 2026] [security2:error] [pid 3262:tid 3262] [client 123.108.206.3:54302] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.108.206.3 (+1 hits since last alert)|vintageamptubes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vintageamptubes.com"] [uri "/xmlrpc.php"] [unique_id "aiWwtTwO8iJCJZBQqFDIzwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack