๐ธ๐ช
konseptit
2026-06-11 18:38:21
(2 days ago)
(wordpress) Failed wordpress login from 146.158.113.223 (RU/Russia/-)
Brute-Force
๐บ๐ธ
WeekendWeb
2026-06-11 14:09:23
(2 days ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 13:39:48
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 09:39:42.835092 2026] [security2:error] [pid 23779:tid 23779] [client 146.158.113.223:32591] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 146.158.113.223 (+1 hits since last alert)|pinebrookdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pinebrookdesign.com"] [uri "/xmlrpc.php"] [unique_id "aiq6nlKZTPz5bBLeFaqExgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-06-11 11:07:32
(2 days ago)
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 16:13:41
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 12:13:34.993591 2026] [security2:error] [pid 16743:tid 16743] [client 146.158.113.223:51998] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 146.158.113.223 (+1 hits since last alert)|intothebigempty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "intothebigempty.com"] [uri "/xmlrpc.php"] [unique_id "aimNLnF7R-oMFAI-vp7X8QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 14:23:27
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 10:23:21.707919 2026] [security2:error] [pid 16441:tid 16455] [client 146.158.113.223:32955] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 146.158.113.223 (+1 hits since last alert)|neotienda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "neotienda.com"] [uri "/xmlrpc.php"] [unique_id "ailzWf-LZq1A3oCNdHknCAAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 13:57:53
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 09:57:45.506842 2026] [security2:error] [pid 848:tid 848] [client 146.158.113.223:42846] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 146.158.113.223 (+1 hits since last alert)|ruthbalser.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ruthbalser.org"] [uri "/xmlrpc.php"] [unique_id "ailtWc6iXIVRrFba7PKeugAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 12:03:49
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 08:03:44.202520 2026] [security2:error] [pid 29388:tid 29493] [client 146.158.113.223:33497] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 146.158.113.223 (+1 hits since last alert)|worldecom.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "worldecom.org"] [uri "/xmlrpc.php"] [unique_id "ailSoFuIrYI-CNOAVmAifAAAAgk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-09 21:56:50
(4 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
RU/Russia/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 21:02:21
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 17:02:17.866326 2026] [security2:error] [pid 28276:tid 28276] [client 146.158.113.223:52447] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 146.158.113.223 (+1 hits since last alert)|littlecreekrvranch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "littlecreekrvranch.com"] [uri "/xmlrpc.php"] [unique_id "aih_WS8SHhXb4_zsO15byAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 20:25:16
(4 days ago)
Fail2ban filtered
...
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-09 19:55:04
(4 days ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 18:16:04
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 146.158.113.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 14:16:01.146387 2026] [security2:error] [pid 14926:tid 14926] [client 146.158.113.223:15943] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 146.158.113.223 (+1 hits since last alert)|manosentuayuda.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "manosentuayuda.org"] [uri "/xmlrpc.php"] [unique_id "aihYYRSA4qyVM4JPf6BC_wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 13:57:08
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ซ๐ท
YF
2026-06-09 10:30:36
(4 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force