Anonymous
2026-06-27 07:20:59
(9 hours ago)
(wordpress) Failed wordpress login from 152.32.99.237 (PH/Philippines/237.99.32.152.convergeict.com)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-27 03:46:01
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 23:45:57.314908 2026] [security2:error] [pid 988:tid 988] [client 152.32.99.237:9204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 152.32.99.237 (+1 hits since last alert)|fgrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fgrotary.org"] [uri "/xmlrpc.php"] [unique_id "aj9HdYgrp5NvGX84lN-fiQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 00:29:33
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 20:29:26.679235 2026] [security2:error] [pid 32549:tid 32549] [client 152.32.99.237:6210] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 152.32.99.237 (+1 hits since last alert)|dalessalesandservice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dalessalesandservice.com"] [uri "/xmlrpc.php"] [unique_id "aj8ZZsPWGmGDkzVrCj-VhAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-26 03:34:09
(1 day ago)
Attac
Brute-Force
๐ง๐ช
cmbplf
2026-06-26 02:33:07
(1 day ago)
5.018 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-26 00:32:55
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 20:32:47.822757 2026] [security2:error] [pid 4765:tid 4789] [client 152.32.99.237:6346] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 152.32.99.237 (+1 hits since last alert)|willmanlawfirm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "willmanlawfirm.com"] [uri "/xmlrpc.php"] [unique_id "aj3Ir7pYK2IYLvkqTI-sLQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-06-25 23:35:16
(1 day ago)
152.32.99.237 - - [25/Jun/2026:18:26:44 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4739 "-" "WordPress.c ...
show more
152.32.99.237 - - [25/Jun/2026:18:26:44 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4739 "-" "WordPress.com; https://wordpress.com"
152.32.99.237 - - [25/Jun/2026:18:28:52 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4739 "-" "Jetpack by WordPress.com"
152.32.99.237 - - [25/Jun/2026:18:31:00 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4740 "-" "WordPress.com; https://wordpress.com"
152.32.99.237 - - [25/Jun/2026:18:33:08 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4738 "-" "Jetpack by WordPress.com"
152.32.99.237 - - [25/Jun/2026:18:35:16 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4739 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 23:00:32
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 19:00:27.575849 2026] [security2:error] [pid 30732:tid 30732] [client 152.32.99.237:3214] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 152.32.99.237 (+1 hits since last alert)|versallis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "versallis.com"] [uri "/xmlrpc.php"] [unique_id "aj2zC6yeSXLfU5UWHJpZIwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-25 22:58:48
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
abdubhai
2026-06-25 02:23:07
(2 days ago)
152.32.99.237 - - [25/Jun/2026:0
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-25 00:47:22
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 20:47:18.741990 2026] [security2:error] [pid 24614:tid 24614] [client 152.32.99.237:6613] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 152.32.99.237 (+1 hits since last alert)|websitesforauthors.design|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "websitesforauthors.design"] [uri "/xmlrpc.php"] [unique_id "ajx6lgGgc6QsTlPtrWxFmQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-06-25 00:00:34
(2 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-24 23:22:41
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 19:22:38.351352 2026] [security2:error] [pid 1231:tid 1231] [client 152.32.99.237:6503] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 152.32.99.237 (+1 hits since last alert)|plazahacienda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "plazahacienda.com"] [uri "/xmlrpc.php"] [unique_id "ajxmvnz3nvpU8E_tCxb8zQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 08:07:36
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 04:07:30.858707 2026] [security2:error] [pid 7024:tid 7035] [client 152.32.99.237:6277] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 152.32.99.237 (+1 hits since last alert)|danelandia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "danelandia.com"] [uri "/xmlrpc.php"] [unique_id "ajuQQquX6-8v1pKxSUe0JAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 06:40:58
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 152.32.99.237 (237.99.32.152.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 02:40:50.673912 2026] [security2:error] [pid 22810:tid 22810] [client 152.32.99.237:6200] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 152.32.99.237 (+1 hits since last alert)|apexandroids.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "apexandroids.com"] [uri "/xmlrpc.php"] [unique_id "ajt78nB6KbTNLDplPqpYRgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack