๐บ๐ธ
TPI-Abuse
2026-06-27 19:35:25
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 163.61.1.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.1.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 15:35:18.515705 2026] [security2:error] [pid 32643:tid 32643] [client 163.61.1.6:51966] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.1.6 (+1 hits since last alert)|naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "naominixon.com"] [uri "/xmlrpc.php"] [unique_id "akAl9jqFNYybl64_ln1IOgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-27 16:01:01
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-27 16:00:58
(1 day ago)
(wordpress) Failed wordpress login from 163.61.1.6 (PK/Pakistan/Punjab/Harunabad/-/[redacted])
Brute-Force
๐ช๐ธ
masterguru
2026-06-27 15:36:16
(1 day ago)
(xmlrpc) Failed xmlrpc access from 163.61.1.6 (PK/Pakistan/-): 5 in the last 3600 secs (0-122)
Hacking
๐ฉ๐ช
Marc
2026-06-27 15:32:46
(1 day ago)
163.61.1.6 - - [27/Jun/2026:17:32:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3296 "-" "Jetpack/12.5; ...
show more
163.61.1.6 - - [27/Jun/2026:17:32:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3296 "-" "Jetpack/12.5; WordPress/6.3; http://site62824763.com" 163.61.1.6 - - [27/Jun/2026:17:32:34 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3295 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)" 163.61.1.6 - - [27/Jun/2026:17:32:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3295 "-" "Jetpack/12.0; WordPress/6.2; http://site18467725.com"
show less
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-26 23:03:31
(2 days ago)
(wordpress) Failed wordpress login from 163.61.1.6 (PK/Pakistan/-)
Brute-Force
๐บ๐ธ
cwytech
2026-06-26 21:31:00
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-06-25 17:47:01
(3 days ago)
163.61.1.6 - - [25/Jun/2026:19:46:40 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3243 "-" "Jetpack/13.0; ...
show more
163.61.1.6 - - [25/Jun/2026:19:46:40 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3243 "-" "Jetpack/13.0; WordPress/6.1; http://site39085807.com" 163.61.1.6 - - [25/Jun/2026:19:46:49 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3244 "-" "WordPress.com; https://wordpress.com" 163.61.1.6 - - [25/Jun/2026:19:47:00 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3245 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-06-25 17:13:19
(3 days ago)
[ThuJun2519:13:15.9843972026][security2:error][pid1542828:tid1542963][client163.61.1.6:0]ModSecurity ...
show more
[ThuJun2519:13:15.9843972026][security2:error][pid1542828:tid1542963][client163.61.1.6:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"martinairsagl.ch\"][uri\"/xmlrpc.php\"][unique_id\"aj1hq3dkUeppgVCMK3ZezwAAAEA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 22:18:20
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 163.61.1.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.1.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 18:18:13.135348 2026] [security2:error] [pid 20990:tid 20990] [client 163.61.1.6:57662] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.1.6 (+1 hits since last alert)|celltechs.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celltechs.net"] [uri "/xmlrpc.php"] [unique_id "ajxXpcZvlcBhRYPiBxXkOwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 22:03:53
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 163.61.1.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.1.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 18:03:48.964517 2026] [security2:error] [pid 10935:tid 10935] [client 163.61.1.6:55006] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.1.6 (+1 hits since last alert)|fishleadership.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fishleadership.org"] [uri "/xmlrpc.php"] [unique_id "ajsCxJhs0A_ZVM3n_jQNhwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-23 16:50:10
(5 days ago)
Attac
Brute-Force
๐บ๐ธ
kosada.com
2026-06-21 18:25:35
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TAY
2026-06-20 21:18:03
(1 week ago)
163.61.1.6 - - [21/Jun/2026:05:17:43 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by Wor ...
show more
163.61.1.6 - - [21/Jun/2026:05:17:43 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
163.61.1.6 - - [21/Jun/2026:05:17:52 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
163.61.1.6 - - [21/Jun/2026:05:18:02 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-20 17:28:08
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 163.61.1.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.1.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 13:28:04.411634 2026] [security2:error] [pid 24744:tid 24744] [client 163.61.1.6:51595] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.1.6 (+1 hits since last alert)|brandoncomputergeeks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "brandoncomputergeeks.com"] [uri "/xmlrpc.php"] [unique_id "ajbNpNcA6cRpQu1yCQKQIgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack