๐บ๐ธ
jsjdmediallc
2026-07-30 20:40:03
(12 hours ago)
Auto-blocked: score 466 (threshold 10). Tier: HIGH. Hits: 92. Flags: xmlrpc, xmlrpc-burst, single-pa ...
show more
Auto-blocked: score 466 (threshold 10). Tier: HIGH. Hits: 92. Flags: xmlrpc, xmlrpc-burst, single-path-flood. Paths: /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-07-30 20:22:29
(12 hours ago)
Wordpress Vunerability attack
Web App Attack
๐ซ๐ฎ
YF
2026-07-30 20:00:40
(13 hours ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-30 16:48:18
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com ...
show more
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:48:14.888922 2026] [security2:error] [pid 4163757:tid 4163757] [client 149.40.63.199:34512] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.40.63.199 (+1 hits since last alert)|yerevanpress.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yerevanpress.am"] [uri "/xmlrpc.php"] [unique_id "amuATgblGkJrOy2mu2nPCwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 16:17:47
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com ...
show more
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:17:42.258280 2026] [security2:error] [pid 477412:tid 477412] [client 149.40.63.199:34858] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.40.63.199 (+1 hits since last alert)|goldcountrygermanamericanclub.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "goldcountrygermanamericanclub.org"] [uri "/xmlrpc.php"] [unique_id "amt5JmXjpgnGdWdZNi234wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-30 16:17:10
(17 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-30 14:46:23
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com ...
show more
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 10:46:17.991494 2026] [security2:error] [pid 3790996:tid 3790996] [client 149.40.63.199:40644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.40.63.199 (+1 hits since last alert)|toepferlab.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "toepferlab.org"] [uri "/xmlrpc.php"] [unique_id "amtjuXitlkztnipzdZJMZQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-30 14:22:04
(18 hours ago)
Wordfence waf block on pameganslaw
Web App Attack
๐ช๐ธ
alferez
2026-07-30 13:13:28
(20 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 03:49:17
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com ...
show more
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 23:49:09.343178 2026] [security2:error] [pid 13916:tid 13939] [client 149.40.63.199:56850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.40.63.199 (+1 hits since last alert)|whatismetamodern.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whatismetamodern.com"] [uri "/xmlrpc.php"] [unique_id "amrJtYwWSYvEx8VxZy48gQAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-07-30 00:01:57
(1 day ago)
5.050 post requests in 1 hour (1yr10mos3w)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-29 21:41:02
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com ...
show more
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:40:56.252555 2026] [security2:error] [pid 3939014:tid 3939014] [client 149.40.63.199:57156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.40.63.199 (+1 hits since last alert)|hookedupfishing.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hookedupfishing.net"] [uri "/xmlrpc.php"] [unique_id "ampzaEfoOdMalvlZcNCfuwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-07-29 19:06:50
(1 day ago)
149.40.63.199 - - [29/Jul/2026:21:06:28 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4615 "-" "Jetpack by ...
show more
149.40.63.199 - - [29/Jul/2026:21:06:28 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4615 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)" 149.40.63.199 - - [29/Jul/2026:21:06:39 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4614 "-" "WordPress.com; https://wordpress.com" 149.40.63.199 - - [29/Jul/2026:21:06:49 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4614 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 17:05:47
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com ...
show more
(mod_security) mod_security (id:240335) triggered by 149.40.63.199 (unn-149-40-63-199.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 13:05:42.695730 2026] [security2:error] [pid 3651076:tid 3651076] [client 149.40.63.199:53190] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 149.40.63.199 (+1 hits since last alert)|soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soonerstone.com"] [uri "/xmlrpc.php"] [unique_id "amoy5gLa6mTzkIwuFwemOAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-29 16:33:21
(1 day ago)
(wordpress) Failed wordpress login from 149.40.63.199 (GB/United Kingdom/unn-149-40-63-199.datapacke ...
show more
(wordpress) Failed wordpress login from 149.40.63.199 (GB/United Kingdom/unn-149-40-63-199.datapacket.com): (CF_ENABLE)
show less
Brute-Force