๐บ๐ธ
TPI-Abuse
2026-06-15 15:30:56
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 149.13.200.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 149.13.200.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 11:30:52.433783 2026] [security2:error] [pid 14982:tid 14982] [client 149.13.200.22:28649] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.13.200.22 (+1 hits since last alert)|d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "d-sinema.com"] [uri "/xmlrpc.php"] [unique_id "ajAarItQSTbC4vfOEhmnRgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 20:13:12
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 149.13.200.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 149.13.200.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 16:13:08.887693 2026] [security2:error] [pid 19304:tid 19316] [client 149.13.200.22:12499] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.13.200.22 (+1 hits since last alert)|michaelrandon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michaelrandon.com"] [uri "/xmlrpc.php"] [unique_id "ai8LVAmhlCfpTyhf9fRrrgAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 17:02:37
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 149.13.200.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 149.13.200.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 13:02:32.896251 2026] [security2:error] [pid 25531:tid 25531] [client 149.13.200.22:12479] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.13.200.22 (+1 hits since last alert)|greatchristianadventure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greatchristianadventure.com"] [uri "/xmlrpc.php"] [unique_id "ai7eqHzBkFbc5CDNLVJmdAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 12:02:33
(3 days ago)
(wordpress) Failed wordpress login from 149.13.200.22 (GB/United Kingdom/-)
Brute-Force
๐ฉ๐ช
reznekcs
2026-06-14 11:59:01
(3 days ago)
F2B wordpress ban. Logs: 149.13.200.22 - - [14/Jun/2026:13:58:52 +0200] "POST /xmlrpc.php HTTP/1.1" ...
show more
F2B wordpress ban. Logs: 149.13.200.22 - - [14/Jun/2026:13:58:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4246 "-" "Jetpack by WordPress.com"
149.13.200.22 - - [14/Jun/2026:13:59:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4246 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 17:04:51
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 149.13.200.22 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 149.13.200.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 13:04:44.219266 2026] [security2:error] [pid 4202:tid 4202] [client 149.13.200.22:26704] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.13.200.22 (+1 hits since last alert)|firebelly.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "firebelly.org"] [uri "/xmlrpc.php"] [unique_id "ai2NrHlBrDH8cyuKDsqjUwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-13 17:01:27
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
security.yc3a.com
2026-04-24 02:07:07
(1 month ago)
149.13.200.22 - - [24/Apr/2026:02:07:06 +0000] "GET /api/images/ HTTP/2.0" 401 16 "-" "Mozilla/5.0 ( ...
show more
149.13.200.22 - - [24/Apr/2026:02:07:06 +0000] "GET /api/images/ HTTP/2.0" 401 16 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 Instagram 263.1.0.14.103 (iPhone15,2; iOS 16_1_1; fr_FR; fr-FR; scale=3.00; 1179x2556; 428326971)"
show less
Brute-Force
Web App Attack