๐ณ๐ฑ
Site.eu
2026-05-27 09:45:36
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-26 07:40:42
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 03:40:37.030959 2026] [security2:error] [pid 24248:tid 24248] [client 123.252.137.22:23755] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.252.137.22 (+1 hits since last alert)|linhsbridal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "linhsbridal.com"] [uri "/xmlrpc.php"] [unique_id "ahVOdWm00UfNDFqWVkJ5PQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-26 04:49:14
(1 week ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-25 09:03:43
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 05:03:36.426271 2026] [security2:error] [pid 30042:tid 30042] [client 123.252.137.22:63971] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.252.137.22 (+1 hits since last alert)|alafiariverrendezvous.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "alafiariverrendezvous.org"] [uri "/xmlrpc.php"] [unique_id "ahQQaBHzrgKcL71UrmwmLwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 06:37:54
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 02:37:47.764856 2026] [security2:error] [pid 24447:tid 24463] [client 123.252.137.22:8640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.252.137.22 (+1 hits since last alert)|hmpdecors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hmpdecors.com"] [uri "/xmlrpc.php"] [unique_id "ahPuO4gtPwYuyc-GFigpsgAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-25 03:44:23
(1 week ago)
Attac
Brute-Force
๐ณ๐ฑ
wlt-blocker
2026-05-25 03:44:21
(1 week ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
integrantservices.com
2026-05-22 10:46:13
(1 week ago)
(wordpress) Failed wordpress login from 123.252.137.22 (IN/India/sagecap.in)
Brute-Force
Anonymous
2026-05-21 10:20:15
(2 weeks ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-21 06:37:03
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 02:36:56.739628 2026] [security2:error] [pid 22315:tid 22315] [client 123.252.137.22:58977] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.252.137.22 (+1 hits since last alert)|abilityimprinting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abilityimprinting.com"] [uri "/xmlrpc.php"] [unique_id "ag6oCHxmzfHedtKHcm5LCgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-20 04:19:24
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-05-18 07:44:18
(2 weeks ago)
Attac
Brute-Force
Anonymous
2026-05-18 05:05:18
(2 weeks ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (146/60 min)'; Requests=146
Port Scan
๐ณ๐ฑ
Site.eu
2026-05-15 08:35:58
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-14 07:45:25
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 123.252.137.22 (sagecap.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 03:45:16.511272 2026] [security2:error] [pid 32363:tid 32363] [client 123.252.137.22:49419] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 123.252.137.22 (+1 hits since last alert)|raintechgutters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "raintechgutters.com"] [uri "/xmlrpc.php"] [unique_id "agV9jJWBXE9_msomU5V0LAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack