Anonymous
2026-09-14 15:00:50
(4 days ago)
Large-scale coordinated botnet (5M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show more
Large-scale coordinated botnet (5M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]): Retaliation after theft; Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]): Employed by Angara Technologies Group | Catalog Search Abuse Blocked: /catalogsearch/result/?cat=33&dir=asc&mode=grid+&order=relevance&projector_type=62&q=crestron+mt-1000c | UA: Mozilla/5.0 (X11; Linux i686) AppleWebKit/536.0 (KHTML, like Gecko) Chrome/49.0.865.0 Safari/536.0 | (Magento Site)
show less
Hacking
Bad Web Bot
π«π·
Kenshin869
2026-05-24 20:36:55
(3 months ago)
Wordpress unauthorized access attempt
Brute-Force
Anonymous
2026-05-24 14:56:40
(3 months ago)
Attac
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-24 13:32:53
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 09:32:50.218101 2026] [security2:error] [pid 6849:tid 6849] [client 151.255.68.135:8551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 151.255.68.135 (+1 hits since last alert)|sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sharawi-gum.com"] [uri "/xmlrpc.php"] [unique_id "ahL-AhUy0qygKSfdcTBOngAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-24 09:43:34
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 05:43:28.918989 2026] [security2:error] [pid 3778:tid 3778] [client 151.255.68.135:5654] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dragonflytunes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dragonflytunes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahLIQJtBFrrcOiFs3CJMngAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-24 05:48:21
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 01:48:15.482067 2026] [security2:error] [pid 16299:tid 16299] [client 151.255.68.135:2314] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 151.255.68.135 (+1 hits since last alert)|investorsfundingusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "investorsfundingusa.com"] [uri "/xmlrpc.php"] [unique_id "ahKRH9XGF-dMjN7qpu9k4wAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-24 04:44:12
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 00:44:05.986810 2026] [security2:error] [pid 380:tid 380] [client 151.255.68.135:8517] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 151.255.68.135 (+1 hits since last alert)|qcyprus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "qcyprus.com"] [uri "/xmlrpc.php"] [unique_id "ahKCFZGTnvz5TVf8moMLSgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-05-24 03:27:01
(3 months ago)
2.820 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-24 01:47:57
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 21:47:51.253727 2026] [security2:error] [pid 27048:tid 27048] [client 151.255.68.135:4865] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 151.255.68.135 (+1 hits since last alert)|drayvian.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "drayvian.com"] [uri "/xmlrpc.php"] [unique_id "ahJYx4MGQ-Tkk2UGHilH9gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-05-23 21:09:56
(3 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
SA/Saudi Arabia/-
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-23 14:49:31
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 151.255.68.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 10:49:27.131638 2026] [security2:error] [pid 25131:tid 25131] [client 151.255.68.135:7925] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 151.255.68.135 (+1 hits since last alert)|vanmeer.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vanmeer.info"] [uri "/xmlrpc.php"] [unique_id "ahG-d8K-nuf_Uu4YMxoBlQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-05-23 13:18:41
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-05-23 09:35:27
(3 months ago)
Attac
Brute-Force