๐ณ๐ฟ
Tripwire
2026-06-07 14:31:19
(15 hours ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 15:54:56
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 11:54:50.054184 2026] [security2:error] [pid 10089:tid 10089] [client 129.205.24.199:6741] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 129.205.24.199 (+1 hits since last alert)|mirai-labo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mirai-labo.com"] [uri "/xmlrpc.php"] [unique_id "aiRCymNZa5Dyc9BfKuga1wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-06-06 15:50:33
(1 day ago)
(wordpress) Failed wordpress login from 129.205.24.199 (UG/Uganda/-)
Brute-Force
Anonymous
2026-06-05 12:06:17
(2 days ago)
Attac
Brute-Force
Anonymous
2026-06-05 11:38:07
(2 days ago)
[ssd1.kdns.gr] httpd-xmlrpc-post: sites=asteres.gr; logs=/var/log/httpd/domains/asteres.gr.log; samp ...
show more
[ssd1.kdns.gr] httpd-xmlrpc-post: sites=asteres.gr; logs=/var/log/httpd/domains/asteres.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 09:12:34
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 05:12:28.835261 2026] [security2:error] [pid 17018:tid 17018] [client 129.205.24.199:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 129.205.24.199 (+1 hits since last alert)|local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "local639.com"] [uri "/xmlrpc.php"] [unique_id "aiKS_N8wzS-GDY0IAJ0eKwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-05 09:11:16
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ช๐ธ
alferez
2026-06-04 15:51:35
(3 days ago)
Multiple WP Login Attack
Brute-Force
๐ณ๐ฑ
wlt-blocker
2026-06-04 14:47:16
(3 days ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 13:49:08
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 09:48:58.792182 2026] [security2:error] [pid 26105:tid 26105] [client 129.205.24.199:25658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 129.205.24.199 (+1 hits since last alert)|internetnameregistration.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "internetnameregistration.com"] [uri "/xmlrpc.php"] [unique_id "aiGCSk7kYl6OkFK2i_r36gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-06-04 13:48:45
(3 days ago)
(xmlrpc) Failed xmlrpc access from 129.205.24.199 (UG/Uganda/-): 5 in the last 3600 secs (0-122)
Hacking
๐ซ๐ท
masterguru
2026-06-04 09:54:43
(3 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 129.205.24.199 (UG/Uganda/-): 10 in the last 3600 secs (0 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 129.205.24.199 (UG/Uganda/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-03 14:07:56
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 10:07:47.207340 2026] [security2:error] [pid 8519:tid 8551] [client 129.205.24.199:24912] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 129.205.24.199 (+1 hits since last alert)|whatismetamodern.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whatismetamodern.com"] [uri "/xmlrpc.php"] [unique_id "aiA1MxejY9tJllTopho0CQAAAYM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 08:04:33
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 04:04:28.052372 2026] [security2:error] [pid 10963:tid 10963] [client 129.205.24.199:20696] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 129.205.24.199 (+1 hits since last alert)|fredlandia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fredlandia.com"] [uri "/xmlrpc.php"] [unique_id "ah_gDN6ICz80yHyEbB9e2AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:59:39
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 129.205.24.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:59:30.715334 2026] [security2:error] [pid 25622:tid 25622] [client 129.205.24.199:6405] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 129.205.24.199 (+1 hits since last alert)|geodogs.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "geodogs.org"] [uri "/xmlrpc.php"] [unique_id "ah8L8nLLmYJvY9n5s7ecswAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack