๐ซ๐ท
dynamix
2026-06-24 09:06:12
(1 hour ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-24 08:35:21
(1 hour ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PH/Philippines/5.116.158.136.convergeict.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 08:25:17
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 136.158.116.5 (5.116.158.136.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 136.158.116.5 (5.116.158.136.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 04:25:03.356755 2026] [security2:error] [pid 17542:tid 17542] [client 136.158.116.5:4779] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 136.158.116.5 (+1 hits since last alert)|pixelspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pixelspective.com"] [uri "/xmlrpc.php"] [unique_id "ajuUX49kSgUxnE49ZVbyhQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-24 08:22:12
(1 hour ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-24 08:04:08
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.158.116.5 (5.116.158.136.convergeict.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 136.158.116.5 (5.116.158.136.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 04:04:02.856313 2026] [security2:error] [pid 19908:tid 19908] [client 136.158.116.5:18746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fatcaverecords.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fatcaverecords.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajuPcpJ8sFc0O4VlxiguDQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 07:35:14
(2 hours ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-24 04:19:15
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 136.158.116.5 (5.116.158.136.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 136.158.116.5 (5.116.158.136.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 00:19:07.638482 2026] [security2:error] [pid 23927:tid 23927] [client 136.158.116.5:61995] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 136.158.116.5 (+1 hits since last alert)|lajoze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lajoze.com"] [uri "/xmlrpc.php"] [unique_id "ajtau_PWupJphzQjvHS5-gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-24 03:23:31
(6 hours ago)
4.091 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-24 01:25:44
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 136.158.116.5 (5.116.158.136.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 136.158.116.5 (5.116.158.136.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 21:25:38.534194 2026] [security2:error] [pid 9744:tid 9744] [client 136.158.116.5:62617] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 136.158.116.5 (+1 hits since last alert)|theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theamarals.com"] [uri "/xmlrpc.php"] [unique_id "ajsyEnD7glPTopkramfpwwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(4 weeks ago)
Aisuru(Mirai variant) DDoS | Incident ID: 5b730afc-5cec-4742-843f-18085cc64e5c
DDoS Attack
๐ฌ๐ง
PeravixGroup
2026-05-06 03:24:13
(1 month ago)
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: ME ...
show more
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: MEDIUM. Aaran.cloud
show less
IoT Targeted
Brute-Force
๐บ๐ธ
floreriaexpress
2026-04-27 12:31:51
(1 month ago)
FakeADS-Anti: country:PH | https://floreriaexpresschile.cl/product/desayuno-vegano
Bad Web Bot
๐บ๐ธ
matt
2026-03-03 22:48:45
(3 months ago)
DDOS attack with query parameters attempting to overload WordPress site.
DDoS Attack
๐บ๐ธ
RAP
2026-01-14 11:51:23
(5 months ago)
2026-01-14 11:51:23 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
๐บ๐ธ
MPL
2026-01-13 07:43:44
(5 months ago)
tcp/23 (2 or more attempts)
Port Scan